2022-12-17T23:50:16Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:50:16Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:50:16Z DEBUG httpd is not configured 2022-12-17T23:50:16Z DEBUG kadmin is not configured 2022-12-17T23:50:16Z DEBUG dirsrv is not configured 2022-12-17T23:50:16Z DEBUG pki-tomcatd is not configured 2022-12-17T23:50:16Z DEBUG install is not configured 2022-12-17T23:50:16Z DEBUG krb5kdc is not configured 2022-12-17T23:50:16Z DEBUG named is not configured 2022-12-17T23:50:16Z DEBUG filestore is tracking no files 2022-12-17T23:50:16Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2022-12-17T23:50:16Z DEBUG svmem(total=8307077120, available=7628124160, percent=8.2, used=416657408, free=6783422464, active=499351552, inactive=682414080, buffers=5562368, cached=1101434880, shared=2465792, slab=154349568) 2022-12-17T23:50:16Z DEBUG Available memory is 7628124160B 2022-12-17T23:50:16Z DEBUG Searching for an interface of IP address: ::1 2022-12-17T23:50:16Z DEBUG Testing local IP address: ::1/128 (interface: lo) 2022-12-17T23:50:16Z DEBUG Starting external process 2022-12-17T23:50:16Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:50:16Z DEBUG Process finished, return code=0 2022-12-17T23:50:16Z DEBUG stdout= 2022-12-17T23:50:16Z DEBUG stderr= 2022-12-17T23:50:16Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:50:16Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:50:16Z DEBUG httpd is not configured 2022-12-17T23:50:16Z DEBUG kadmin is not configured 2022-12-17T23:50:16Z DEBUG dirsrv is not configured 2022-12-17T23:50:16Z DEBUG pki-tomcatd is not configured 2022-12-17T23:50:16Z DEBUG install is not configured 2022-12-17T23:50:16Z DEBUG krb5kdc is not configured 2022-12-17T23:50:16Z DEBUG named is not configured 2022-12-17T23:50:16Z DEBUG filestore is tracking no files 2022-12-17T23:50:16Z DEBUG Starting external process 2022-12-17T23:50:16Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ntpd.service'] 2022-12-17T23:50:16Z DEBUG Process finished, return code=1 2022-12-17T23:50:16Z DEBUG stdout= 2022-12-17T23:50:16Z DEBUG stderr=Failed to get unit file state for ntpd.service: No such file or directory 2022-12-17T23:50:16Z DEBUG Starting external process 2022-12-17T23:50:16Z DEBUG args=['/bin/systemctl', 'is-active', 'ntpd.service'] 2022-12-17T23:50:16Z DEBUG Process finished, return code=3 2022-12-17T23:50:16Z DEBUG stdout=inactive 2022-12-17T23:50:16Z DEBUG stderr= 2022-12-17T23:50:16Z DEBUG Starting external process 2022-12-17T23:50:16Z DEBUG args=['/bin/systemctl', 'is-enabled', 'systemd-timesyncd.service'] 2022-12-17T23:50:16Z DEBUG Process finished, return code=1 2022-12-17T23:50:16Z DEBUG stdout=disabled 2022-12-17T23:50:16Z DEBUG stderr= 2022-12-17T23:50:16Z DEBUG Starting external process 2022-12-17T23:50:16Z DEBUG args=['/bin/systemctl', 'is-active', 'systemd-timesyncd.service'] 2022-12-17T23:50:16Z DEBUG Process finished, return code=3 2022-12-17T23:50:16Z DEBUG stdout=inactive 2022-12-17T23:50:16Z DEBUG stderr= 2022-12-17T23:50:16Z DEBUG Check if master.redacted_domain.com is a primary hostname for localhost 2022-12-17T23:50:17Z DEBUG Primary hostname for localhost: master.redacted_domain.com 2022-12-17T23:50:20Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:50:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:50:20Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:50:20Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:50:20Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:50:20Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:50:21Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:50:21Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:50:21Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:50:21Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:50:21Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:50:21Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:50:21Z DEBUG check_port_bindable: Checking IPv4/IPv6 dual stack and TCP 2022-12-17T23:50:21Z DEBUG check_port_bindable: bind success: 8443/TCP 2022-12-17T23:50:21Z DEBUG check_port_bindable: Checking IPv4/IPv6 dual stack and TCP 2022-12-17T23:50:21Z DEBUG check_port_bindable: bind success: 8080/TCP 2022-12-17T23:50:21Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:50:21Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:50:21Z DEBUG Starting external process 2022-12-17T23:50:21Z DEBUG args=['pki-server', 'subsystem-show', 'kra'] 2022-12-17T23:50:22Z DEBUG Process finished, return code=1 2022-12-17T23:50:22Z DEBUG stdout= 2022-12-17T23:50:22Z DEBUG stderr=ERROR: Invalid instance pki-tomcat. 2022-12-17T23:50:22Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:50:22Z INFO Checking DNS domain redacted_domain.com., please wait ... 2022-12-17T23:50:22Z WARNING DNS zone redacted_domain.com. already exists in DNS and is handled by server(s): ['graham.ns.cloudflare.com.', 'sonia.ns.cloudflare.com.'] Please make sure that the domain is properly delegated to this IPA server. 2022-12-17T23:50:22Z DEBUG Name master.redacted_domain.com resolved to {UnsafeIPAddress('172.16.0.21'), UnsafeIPAddress('fe80::5054:ff:fe00:10')} 2022-12-17T23:50:22Z WARNING Invalid IP address fe80::5054:ff:fe00:10 for master.redacted_domain.com: cannot use link-local IP address fe80::5054:ff:fe00:10 2022-12-17T23:50:22Z DEBUG Searching for an interface of IP address: 172.16.0.21 2022-12-17T23:50:22Z DEBUG Testing local IP address: 127.0.0.1/255.0.0.0 (interface: lo) 2022-12-17T23:50:22Z DEBUG Testing local IP address: 172.16.0.21/255.240.0.0 (interface: enX0) 2022-12-17T23:50:22Z DEBUG systemd-resolved detected, fetching nameservers from D-Bus 2022-12-17T23:50:22Z DEBUG Detected nameservers: [(2, IPv4Address('172.16.16.172'))] 2022-12-17T23:50:22Z DEBUG Use nameservers ['172.16.16.172'] 2022-12-17T23:50:22Z DEBUG Checking DNS server: 172.16.16.172 2022-12-17T23:50:22Z DEBUG will use DNS forwarders: ['172.16.16.172'] 2022-12-17T23:50:22Z INFO Reverse record for IP address 172.16.0.21 already exists 2022-12-17T23:50:22Z DEBUG LDAP is not connected, can not retrieve NetBIOS name 2022-12-17T23:50:22Z DEBUG Backing up system configuration file '/etc/hostname' 2022-12-17T23:50:22Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:50:22Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:50:22Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:50:22Z DEBUG Starting external process 2022-12-17T23:50:22Z DEBUG args=['/bin/hostnamectl', 'set-hostname', 'master.redacted_domain.com'] 2022-12-17T23:50:22Z DEBUG Process finished, return code=0 2022-12-17T23:50:22Z DEBUG stdout= 2022-12-17T23:50:22Z DEBUG stderr= 2022-12-17T23:50:22Z DEBUG Backing up system configuration file '/etc/hosts' 2022-12-17T23:50:22Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:50:22Z DEBUG Starting external process 2022-12-17T23:50:22Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:50:22Z DEBUG Process finished, return code=0 2022-12-17T23:50:22Z DEBUG stdout= 2022-12-17T23:50:22Z DEBUG stderr= 2022-12-17T23:50:22Z DEBUG Starting external process 2022-12-17T23:50:22Z DEBUG args=['/sbin/restorecon', '/etc/pkcs11/modules/softhsm2.module'] 2022-12-17T23:50:22Z DEBUG Process finished, return code=0 2022-12-17T23:50:22Z DEBUG stdout= 2022-12-17T23:50:22Z DEBUG stderr= 2022-12-17T23:50:22Z DEBUG Created PKCS#11 module config '/etc/pkcs11/modules/softhsm2.module'. 2022-12-17T23:50:24Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:50:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:50:24Z DEBUG Starting external process 2022-12-17T23:50:24Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ntpd.service'] 2022-12-17T23:50:24Z DEBUG Process finished, return code=1 2022-12-17T23:50:24Z DEBUG stdout= 2022-12-17T23:50:24Z DEBUG stderr=Failed to get unit file state for ntpd.service: No such file or directory 2022-12-17T23:50:24Z DEBUG Starting external process 2022-12-17T23:50:24Z DEBUG args=['/bin/systemctl', 'is-active', 'ntpd.service'] 2022-12-17T23:50:24Z DEBUG Process finished, return code=3 2022-12-17T23:50:24Z DEBUG stdout=inactive 2022-12-17T23:50:24Z DEBUG stderr= 2022-12-17T23:50:24Z DEBUG Starting external process 2022-12-17T23:50:24Z DEBUG args=['/bin/systemctl', 'is-enabled', 'systemd-timesyncd.service'] 2022-12-17T23:50:24Z DEBUG Process finished, return code=1 2022-12-17T23:50:24Z DEBUG stdout=disabled 2022-12-17T23:50:24Z DEBUG stderr= 2022-12-17T23:50:24Z DEBUG Starting external process 2022-12-17T23:50:24Z DEBUG args=['/bin/systemctl', 'is-active', 'systemd-timesyncd.service'] 2022-12-17T23:50:24Z DEBUG Process finished, return code=3 2022-12-17T23:50:24Z DEBUG stdout=inactive 2022-12-17T23:50:24Z DEBUG stderr= 2022-12-17T23:50:24Z INFO Synchronizing time 2022-12-17T23:50:24Z DEBUG Starting external process 2022-12-17T23:50:24Z DEBUG args=['/bin/systemctl', 'is-enabled', 'chronyd.service'] 2022-12-17T23:50:24Z DEBUG Process finished, return code=0 2022-12-17T23:50:24Z DEBUG stdout=enabled 2022-12-17T23:50:24Z DEBUG stderr= 2022-12-17T23:50:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:50:24Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:50:24Z DEBUG Configuring chrony 2022-12-17T23:50:24Z DEBUG Setting time servers: 2022-12-17T23:50:24Z DEBUG '' 2022-12-17T23:50:24Z DEBUG Backing up '/etc/chrony.conf' 2022-12-17T23:50:24Z DEBUG Backing up system configuration file '/etc/chrony.conf' 2022-12-17T23:50:24Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:50:24Z DEBUG Writing configuration to '/etc/chrony.conf' 2022-12-17T23:50:24Z ERROR Augeas failed to configure file /etc/chrony.conf 2022-12-17T23:50:24Z DEBUG Starting external process 2022-12-17T23:50:24Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:50:24Z DEBUG Process finished, return code=0 2022-12-17T23:50:24Z DEBUG stdout= 2022-12-17T23:50:24Z DEBUG stderr= 2022-12-17T23:50:24Z DEBUG Starting external process 2022-12-17T23:50:24Z DEBUG args=['/sbin/restorecon', '/etc/chrony.conf'] 2022-12-17T23:50:24Z DEBUG Process finished, return code=0 2022-12-17T23:50:24Z DEBUG stdout= 2022-12-17T23:50:24Z DEBUG stderr= 2022-12-17T23:50:24Z DEBUG Starting external process 2022-12-17T23:50:24Z DEBUG args=['/bin/systemctl', 'enable', 'chronyd.service'] 2022-12-17T23:50:24Z DEBUG Process finished, return code=0 2022-12-17T23:50:24Z DEBUG stdout= 2022-12-17T23:50:24Z DEBUG stderr= 2022-12-17T23:50:24Z DEBUG Starting external process 2022-12-17T23:50:24Z DEBUG args=['/bin/systemctl', 'restart', 'chronyd.service'] 2022-12-17T23:50:24Z DEBUG Process finished, return code=0 2022-12-17T23:50:24Z DEBUG stdout= 2022-12-17T23:50:24Z DEBUG stderr= 2022-12-17T23:50:24Z DEBUG Starting external process 2022-12-17T23:50:24Z DEBUG args=['/bin/systemctl', 'is-active', 'chronyd.service'] 2022-12-17T23:50:24Z DEBUG Process finished, return code=0 2022-12-17T23:50:24Z DEBUG stdout=active 2022-12-17T23:50:24Z DEBUG stderr= 2022-12-17T23:50:24Z DEBUG Restart of chronyd.service complete 2022-12-17T23:50:24Z INFO Attempting to sync time with chronyc. 2022-12-17T23:50:24Z DEBUG Starting external process 2022-12-17T23:50:24Z DEBUG args=['/usr/bin/chronyc', '-d', 'waitsync', '4', '0', '0', '3'] 2022-12-17T23:50:33Z DEBUG Process finished, return code=0 2022-12-17T23:50:33Z DEBUG stdout=try: 1, refid: 00000000, correction: 0.000000000, skew: 0.000 try: 2, refid: 00000000, correction: 0.000000000, skew: 0.000 try: 3, refid: 00000000, correction: 0.000000000, skew: 0.000 try: 4, refid: B9F27035, correction: 0.001873106, skew: 27.090 2022-12-17T23:50:33Z DEBUG stderr=Resolved 127.0.0.1 to 127.0.0.1 Resolved ::1 to ::1 Could not remove /run/chrony/chronyc.4229.sock : No such file or directory Opened Unix socket fd=3 remote=/run/chrony/chronyd.sock local=/run/chrony/chronyc.4229.sock Sent data fd=3 len=104 Timeout 1.000000 seconds Received data fd=3 len=104 Reply cmd=33 reply=5 stat=0 Sent data fd=3 len=104 Timeout 1.000000 seconds Received data fd=3 len=104 Reply cmd=33 reply=5 stat=0 Sent data fd=3 len=104 Timeout 1.000000 seconds Received data fd=3 len=104 Reply cmd=33 reply=5 stat=0 Sent data fd=3 len=104 Timeout 1.000000 seconds Received data fd=3 len=104 Reply cmd=33 reply=5 stat=0 2022-12-17T23:50:33Z INFO Time synchronization was successful. 2022-12-17T23:50:35Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:50:35Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:50:35Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:50:35Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:50:35Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:50:35Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:50:35Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:50:35Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:50:35Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:50:35Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:50:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:50:36Z DEBUG Configuring directory server (dirsrv). Estimated time: 30 seconds 2022-12-17T23:50:36Z DEBUG [1/42]: creating directory server instance 2022-12-17T23:50:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:50:36Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:50:36Z DEBUG Running setup with verbose 2022-12-17T23:50:36Z DEBUG START: Starting installation ... 2022-12-17T23:50:36Z DEBUG READY: Preparing installation for REDACTED_DOMAIN-COM... 2022-12-17T23:50:36Z INFO Validate installation settings ... 2022-12-17T23:50:36Z DEBUG PASSED: using config settings 999999999 2022-12-17T23:50:36Z DEBUG PASSED: user / group checking 2022-12-17T23:50:36Z DEBUG PASSED: prefix checking 2022-12-17T23:50:36Z DEBUG list() REDACTED_DOMAIN-COM instance not found: missing /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/dse.ldif 2022-12-17T23:50:36Z DEBUG PASSED: instance checking 2022-12-17T23:50:36Z DEBUG INFO: temp root password set to .Zk0ZRmNL2crp1iaDBcQJUPBh9SPyuI5tkwxQi4eHu2hX38RZlvHZURt4gae0s63g 2022-12-17T23:50:36Z DEBUG PASSED: root user checking 2022-12-17T23:50:36Z DEBUG PASSED: network avaliability checking 2022-12-17T23:50:36Z DEBUG READY: Beginning installation for REDACTED_DOMAIN-COM... 2022-12-17T23:50:36Z DEBUG ACTION: Creating dse.ldif 2022-12-17T23:50:36Z INFO Create file system structures ... 2022-12-17T23:50:36Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:50:36Z DEBUG ACTION: creating /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:50:36Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/db 2022-12-17T23:50:36Z DEBUG ACTION: creating /dev/shm/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:50:36Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:50:36Z DEBUG ACTION: creating /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:50:36Z DEBUG ACTION: creating /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:50:36Z DEBUG ACTION: creating /run/dirsrv 2022-12-17T23:50:37Z DEBUG b'CMD: systemctl enable dirsrv@REDACTED_DOMAIN-COM ; STDOUT: ; STDERR: Created symlink /etc/systemd/system/multi-user.target.wants/dirsrv@REDACTED_DOMAIN-COM.service \xe2\x86\x92 /usr/lib/systemd/system/dirsrv@.service.\n' 2022-12-17T23:50:37Z DEBUG ACTION: Creating certificate database is /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:50:37Z DEBUG Allocate with None 2022-12-17T23:50:37Z DEBUG Allocate with /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:50:37Z DEBUG Allocate with localhost:389 2022-12-17T23:50:37Z DEBUG Allocate with localhost:389 2022-12-17T23:50:37Z DEBUG nss cmd: /usr/bin/certutil -N -d /etc/dirsrv/slapd-REDACTED_DOMAIN-COM -f /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/pwdfile.txt -@ /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/pwdfile.txt 2022-12-17T23:50:37Z DEBUG nss output: 2022-12-17T23:50:37Z INFO Perform SELinux labeling ... 2022-12-17T23:50:39Z DEBUG Setting label dirsrv_var_lib_t in SELinux file context /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak. 2022-12-17T23:50:40Z DEBUG Setting label dirsrv_config_t in SELinux file context /etc/dirsrv/slapd-REDACTED_DOMAIN-COM. 2022-12-17T23:50:42Z DEBUG Setting label dirsrv_var_lib_t in SELinux file context /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/db. 2022-12-17T23:50:44Z DEBUG Setting label dirsrv_var_lib_t in SELinux file context /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif. 2022-12-17T23:50:46Z DEBUG Setting label dirsrv_var_lock_t in SELinux file context /var/run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM. 2022-12-17T23:50:47Z DEBUG Setting label dirsrv_var_log_t in SELinux file context /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM. 2022-12-17T23:50:48Z DEBUG Setting label dirsrv_tmpfs_t in SELinux file context /dev/shm/slapd-REDACTED_DOMAIN-COM. 2022-12-17T23:50:50Z DEBUG Setting label dirsrv_var_run_t in SELinux file context /var/run/dirsrv. 2022-12-17T23:50:51Z DEBUG Setting label dirsrv_config_t in SELinux file context /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema. 2022-12-17T23:50:52Z DEBUG port 389 already in [389, 636, 3268, 3269, 7389], skipping port relabel 2022-12-17T23:50:52Z DEBUG asan_enabled=False 2022-12-17T23:50:52Z DEBUG libfaketime installed =False 2022-12-17T23:50:52Z DEBUG systemd status -> True 2022-12-17T23:50:52Z DEBUG systemd status -> True 2022-12-17T23:50:55Z DEBUG open(): Connecting to uri ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:50:55Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:50:55Z DEBUG Using external ca certificate /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:50:55Z DEBUG Using /etc/openldap/ldap.conf certificate policy 2022-12-17T23:50:55Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 2 2022-12-17T23:50:55Z DEBUG open(): Using root autobind ... 2022-12-17T23:50:55Z DEBUG open(): bound as cn=Directory Manager 2022-12-17T23:50:55Z DEBUG Retrieving entry with [('',)] 2022-12-17T23:50:55Z DEBUG Retrieved entry [dn: vendorVersion: 389-Directory/2.2.4 B2022.322.0000 ] 2022-12-17T23:50:55Z DEBUG open(): Connecting to uri ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:50:55Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:50:55Z DEBUG Using external ca certificate /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:50:55Z DEBUG Using /etc/openldap/ldap.conf certificate policy 2022-12-17T23:50:55Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 2 2022-12-17T23:50:55Z DEBUG open(): Using root autobind ... 2022-12-17T23:50:55Z DEBUG open(): bound as cn=Directory Manager 2022-12-17T23:50:55Z DEBUG Retrieving entry with [('',)] 2022-12-17T23:50:55Z DEBUG Retrieved entry [dn: vendorVersion: 389-Directory/2.2.4 B2022.322.0000 ] 2022-12-17T23:50:55Z DEBUG cn=config set REPLACE: ('nsslapd-secureport', '636') 2022-12-17T23:50:55Z DEBUG Checking "None" under cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config : {'cn': 'entryUUID', 'nsSystemIndex': 'false', 'nsIndexType': ['eq', 'pres']} 2022-12-17T23:50:55Z DEBUG Using first property cn: entryUUID as rdn 2022-12-17T23:50:55Z DEBUG Validated dn cn=entryUUID,cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:50:55Z DEBUG Creating cn=entryUUID,cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:50:55Z DEBUG updating dn: cn=entryUUID,cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:50:55Z DEBUG updated dn: cn=entryUUID,cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config with {'objectclass': [b'top', b'nsIndex']} 2022-12-17T23:50:55Z DEBUG updating dn: cn=entryUUID,cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:50:55Z DEBUG updated dn: cn=entryUUID,cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config with {'cn': [b'entryUUID'], 'nsSystemIndex': [b'false'], 'nsIndexType': [b'eq', b'pres']} 2022-12-17T23:50:55Z DEBUG Created entry cn=entryUUID,cn=default indexes,cn=config,cn=ldbm database,cn=plugins,cn=config : {'objectclass': [b'top', b'nsIndex'], 'cn': [b'entryUUID'], 'nsSystemIndex': [b'false'], 'nsIndexType': [b'eq', b'pres']} 2022-12-17T23:50:55Z INFO Create database backend: dc=redacted_domain,dc=com ... 2022-12-17T23:50:55Z DEBUG Checking "None" under cn=ldbm database,cn=plugins,cn=config : {'cn': 'userRoot', 'nsslapd-suffix': 'dc=redacted_domain,dc=com'} 2022-12-17T23:50:55Z DEBUG Using first property cn: userRoot as rdn 2022-12-17T23:50:55Z DEBUG _gen_selector filter = (&(&(objectclass=nsMappingTree))(|(cn=dc=redacted_domain,dc=com)(nsslapd-backend=dc=redacted_domain,dc=com))) 2022-12-17T23:50:55Z DEBUG _gen_selector filter = (&(&(objectclass=nsMappingTree))(|(cn=userRoot)(nsslapd-backend=userRoot))) 2022-12-17T23:50:55Z DEBUG Validated dn cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:50:55Z DEBUG Creating cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:50:55Z DEBUG updating dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:50:55Z DEBUG updated dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config with {'objectclass': [b'top', b'extensibleObject', b'nsBackendInstance']} 2022-12-17T23:50:55Z DEBUG updating dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:50:55Z DEBUG updated dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config with {'cn': [b'userRoot'], 'nsslapd-suffix': [b'dc=redacted_domain,dc=com']} 2022-12-17T23:50:55Z DEBUG Created entry cn=userRoot,cn=ldbm database,cn=plugins,cn=config : {'objectclass': [b'top', b'extensibleObject', b'nsBackendInstance'], 'cn': [b'userRoot'], 'nsslapd-suffix': [b'dc=redacted_domain,dc=com']} 2022-12-17T23:50:55Z DEBUG Checking "None" under cn=mapping tree,cn=config : {'cn': [b'dc=redacted_domain,dc=com'], 'nsslapd-state': 'backend', 'nsslapd-backend': [b'userRoot']} 2022-12-17T23:50:55Z DEBUG Using first property cn: dc\=redacted_domain\,dc\=com as rdn 2022-12-17T23:50:55Z DEBUG Validated dn cn=dc\=redacted_domain\,dc\=com,cn=mapping tree,cn=config 2022-12-17T23:50:55Z DEBUG Creating cn=dc\=redacted_domain\,dc\=com,cn=mapping tree,cn=config 2022-12-17T23:50:55Z DEBUG updating dn: cn=dc\=redacted_domain\,dc\=com,cn=mapping tree,cn=config 2022-12-17T23:50:55Z DEBUG updated dn: cn=dc\=redacted_domain\,dc\=com,cn=mapping tree,cn=config with {'objectclass': [b'top', b'extensibleObject', b'nsMappingTree']} 2022-12-17T23:50:55Z DEBUG updating dn: cn=dc\=redacted_domain\,dc\=com,cn=mapping tree,cn=config 2022-12-17T23:50:55Z DEBUG updated dn: cn=dc\=redacted_domain\,dc\=com,cn=mapping tree,cn=config with {'cn': [b'dc=redacted_domain,dc=com', b'dc\\=redacted_domain\\,dc\\=com'], 'nsslapd-state': [b'backend'], 'nsslapd-backend': [b'userRoot']} 2022-12-17T23:50:55Z DEBUG Created entry cn=dc\=redacted_domain\,dc\=com,cn=mapping tree,cn=config : {'objectclass': [b'top', b'extensibleObject', b'nsMappingTree'], 'cn': [b'dc=redacted_domain,dc=com', b'dc\\=redacted_domain\\,dc\\=com'], 'nsslapd-state': [b'backend'], 'nsslapd-backend': [b'userRoot']} 2022-12-17T23:50:55Z DEBUG Adding sasl maps for suffix dc=redacted_domain,dc=com 2022-12-17T23:50:55Z DEBUG Checking "None" under cn=mapping,cn=sasl,cn=config : {'cn': 'rfc 2829 u syntax', 'nsSaslMapRegexString': '^u:\\(.*\\)', 'nsSaslMapBaseDNTemplate': 'dc=redacted_domain,dc=com', 'nsSaslMapFilterTemplate': '(uid=\\1)'} 2022-12-17T23:50:55Z DEBUG Using first property cn: rfc 2829 u syntax as rdn 2022-12-17T23:50:55Z DEBUG Validated dn cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2022-12-17T23:50:55Z DEBUG Creating cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2022-12-17T23:50:55Z DEBUG updating dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2022-12-17T23:50:55Z DEBUG updated dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config with {'objectclass': [b'top', b'nsSaslMapping']} 2022-12-17T23:50:55Z DEBUG updating dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2022-12-17T23:50:55Z DEBUG updated dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config with {'cn': [b'rfc 2829 u syntax'], 'nsSaslMapRegexString': [b'^u:\\(.*\\)'], 'nsSaslMapBaseDNTemplate': [b'dc=redacted_domain,dc=com'], 'nsSaslMapFilterTemplate': [b'(uid=\\1)']} 2022-12-17T23:50:55Z DEBUG Created entry cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config : {'objectclass': [b'top', b'nsSaslMapping'], 'cn': [b'rfc 2829 u syntax'], 'nsSaslMapRegexString': [b'^u:\\(.*\\)'], 'nsSaslMapBaseDNTemplate': [b'dc=redacted_domain,dc=com'], 'nsSaslMapFilterTemplate': [b'(uid=\\1)']} 2022-12-17T23:50:55Z DEBUG Checking "None" under cn=mapping,cn=sasl,cn=config : {'cn': 'uid mapping', 'nsSaslMapRegexString': '^[^:@]+$', 'nsSaslMapBaseDNTemplate': 'dc=redacted_domain,dc=com', 'nsSaslMapFilterTemplate': '(uid=&)'} 2022-12-17T23:50:55Z DEBUG Using first property cn: uid mapping as rdn 2022-12-17T23:50:55Z DEBUG Validated dn cn=uid mapping,cn=mapping,cn=sasl,cn=config 2022-12-17T23:50:55Z DEBUG Creating cn=uid mapping,cn=mapping,cn=sasl,cn=config 2022-12-17T23:50:55Z DEBUG updating dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config 2022-12-17T23:50:55Z DEBUG updated dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config with {'objectclass': [b'top', b'nsSaslMapping']} 2022-12-17T23:50:55Z DEBUG updating dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config 2022-12-17T23:50:55Z DEBUG updated dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config with {'cn': [b'uid mapping'], 'nsSaslMapRegexString': [b'^[^:@]+$'], 'nsSaslMapBaseDNTemplate': [b'dc=redacted_domain,dc=com'], 'nsSaslMapFilterTemplate': [b'(uid=&)']} 2022-12-17T23:50:55Z DEBUG Created entry cn=uid mapping,cn=mapping,cn=sasl,cn=config : {'objectclass': [b'top', b'nsSaslMapping'], 'cn': [b'uid mapping'], 'nsSaslMapRegexString': [b'^[^:@]+$'], 'nsSaslMapBaseDNTemplate': [b'dc=redacted_domain,dc=com'], 'nsSaslMapFilterTemplate': [b'(uid=&)']} 2022-12-17T23:50:55Z INFO Perform post-installation tasks ... 2022-12-17T23:50:55Z DEBUG cn=config set REPLACE: ('nsslapd-rootpw', '********') 2022-12-17T23:50:55Z DEBUG systemd status -> True 2022-12-17T23:50:55Z DEBUG systemd status -> True 2022-12-17T23:50:58Z DEBUG systemd status -> True 2022-12-17T23:50:58Z DEBUG systemd status -> True 2022-12-17T23:51:00Z DEBUG 🎉 Instance setup complete 2022-12-17T23:51:00Z DEBUG FINISH: Completed installation for instance: slapd-REDACTED_DOMAIN-COM 2022-12-17T23:51:00Z DEBUG Allocate local instance with ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:51:00Z DEBUG open(): Connecting to uri ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:51:00Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:51:00Z DEBUG Using external ca certificate /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:51:00Z DEBUG Using /etc/openldap/ldap.conf certificate policy 2022-12-17T23:51:00Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 2 2022-12-17T23:51:00Z DEBUG open(): Using root autobind ... 2022-12-17T23:51:00Z DEBUG open(): bound as cn=Directory Manager 2022-12-17T23:51:00Z DEBUG Retrieving entry with [('',)] 2022-12-17T23:51:00Z DEBUG Retrieved entry [dn: vendorVersion: 389-Directory/2.2.4 B2022.322.0000 ] 2022-12-17T23:51:00Z DEBUG Retrieving entry with [('cn=Multisupplier Replication Plugin,cn=plugins,cn=config',)] 2022-12-17T23:51:00Z DEBUG Retrieved entry [dn: cn=Multisupplier Replication Plugin,cn=plugins,cn=config cn: Multisupplier Replication Plugin ] 2022-12-17T23:51:00Z DEBUG Checking "None" under None : {'dc': 'redacted_domain', 'info': 'IPA V2.0'} 2022-12-17T23:51:00Z DEBUG Validated dn dc=redacted_domain,dc=com 2022-12-17T23:51:00Z DEBUG Creating dc=redacted_domain,dc=com 2022-12-17T23:51:00Z DEBUG updating dn: dc=redacted_domain,dc=com 2022-12-17T23:51:00Z DEBUG updated dn: dc=redacted_domain,dc=com with {'objectclass': [b'top', b'domain', b'pilotObject']} 2022-12-17T23:51:00Z DEBUG updating dn: dc=redacted_domain,dc=com 2022-12-17T23:51:00Z DEBUG updated dn: dc=redacted_domain,dc=com with {'dc': [b'redacted_domain'], 'info': [b'IPA V2.0']} 2022-12-17T23:51:00Z DEBUG Created entry dc=redacted_domain,dc=com : {'objectclass': [b'top', b'domain', b'pilotObject'], 'dc': [b'redacted_domain'], 'info': [b'IPA V2.0']} 2022-12-17T23:51:00Z DEBUG completed creating DS instance 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __create_instance 23.81 sec 2022-12-17T23:51:00Z DEBUG [2/42]: tune ldbm plugin 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/ldbm-tuning.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=replace nsslapd-db-locks: 50000 modifying entry "cn=bdb,cn=config,cn=ldbm database,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __tune_ldbm 0.02 sec 2022-12-17T23:51:00Z DEBUG [3/42]: adding default schema 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __add_default_schemas 0.00 sec 2022-12-17T23:51:00Z DEBUG [4/42]: enabling memberof plugin 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/memberof-conf.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=replace nsslapd-pluginenabled: on add memberofgroupattr: memberUser add memberofgroupattr: memberHost add memberofgroupattr: ipaOwner modifying entry "cn=MemberOf Plugin,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __add_memberof_module 0.01 sec 2022-12-17T23:51:00Z DEBUG [5/42]: enabling winsync plugin 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/ipa-winsync-conf.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa-winsync add nsslapd-pluginpath: libipa_winsync add nsslapd-plugininitfunc: ipa_winsync_plugin_init add nsslapd-pluginDescription: Allows IPA to work with the DS windows sync feature add nsslapd-pluginid: ipa-winsync add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-plugin-depends-on-type: database add ipaWinSyncRealmFilter: (objectclass=krbRealmContainer) add ipaWinSyncRealmAttr: cn add ipaWinSyncNewEntryFilter: (cn=ipaConfig) add ipaWinSyncNewUserOCAttr: ipauserobjectclasses add ipaWinSyncUserFlatten: true add ipaWinsyncHomeDirAttr: ipaHomesRootDir add ipaWinsyncLoginShellAttr: ipaDefaultLoginShell add ipaWinSyncDefaultGroupAttr: ipaDefaultPrimaryGroup add ipaWinSyncDefaultGroupFilter: (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) add ipaWinSyncAcctDisable: both add ipaWinSyncForceSync: true add ipaWinSyncUserAttr: uidNumber -1 gidNumber -1 adding new entry "cn=ipa-winsync,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __add_winsync_module 0.01 sec 2022-12-17T23:51:00Z DEBUG [6/42]: configure password logging 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/pw-logging-conf.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=replace nsslapd-unhashed-pw-switch: nolog modifying entry "cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __password_logging 0.01 sec 2022-12-17T23:51:00Z DEBUG [7/42]: configuring replication version plugin 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpt7zzx5t5', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Version Replication add nsslapd-pluginpath: libipa_repl_version add nsslapd-plugininitfunc: repl_version_plugin_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: off add nsslapd-pluginid: ipa_repl_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Replication version plugin add nsslapd-plugin-depends-on-type: database add nsslapd-plugin-depends-on-named: Multisupplier Replication Plugin adding new entry "cn=IPA Version Replication,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __config_version_module 0.26 sec 2022-12-17T23:51:00Z DEBUG [8/42]: enabling IPA enrollment plugin 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpqeb9i_l5', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_enrollment_extop add nsslapd-pluginpath: libipa_enrollment_extop add nsslapd-plugininitfunc: ipaenrollment_init add nsslapd-plugintype: extendedop add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_enrollment_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Enroll hosts into the IPA domain add nsslapd-plugin-depends-on-type: database add nsslapd-realmTree: dc=redacted_domain,dc=com adding new entry "cn=ipa_enrollment_extop,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __add_enrollment_module 0.01 sec 2022-12-17T23:51:00Z DEBUG [9/42]: configuring uniqueness plugin 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpsfhrzl1s', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: krbPrincipalName uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: krbPrincipalName add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=redacted_domain,dc=com add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com add uniqueness-across-all-subtrees: on adding new entry "cn=krbPrincipalName uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: krbCanonicalName uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: krbCanonicalName add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=redacted_domain,dc=com add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com add uniqueness-across-all-subtrees: on adding new entry "cn=krbCanonicalName uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: netgroup uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: cn add uniqueness-subtrees: cn=ng,cn=alt,dc=redacted_domain,dc=com add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values adding new entry "cn=netgroup uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: ipaUniqueID uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: ipaUniqueID add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=redacted_domain,dc=com add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com add uniqueness-across-all-subtrees: on adding new entry "cn=ipaUniqueID uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: sudorule name uniqueness add nsslapd-pluginDescription: Enforce unique attribute values add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: cn add uniqueness-subtrees: cn=sudorules,cn=sudo,dc=redacted_domain,dc=com add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project adding new entry "cn=sudorule name uniqueness,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __set_unique_attrs 0.03 sec 2022-12-17T23:51:00Z DEBUG [10/42]: configuring uuid plugin 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/uuid-conf.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA UUID add nsslapd-pluginpath: libipa_uuid add nsslapd-plugininitfunc: ipauuid_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipauuid_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA UUID plugin add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA UUID,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpnk5uczei', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=add objectclass: top extensibleObject add cn: IPA Unique IDs add ipaUuidAttr: ipaUniqueID add ipaUuidMagicRegen: autogenerate add ipaUuidFilter: (|(objectclass=ipaObject)(objectclass=ipaAssociation)) add ipaUuidScope: dc=redacted_domain,dc=com add ipaUuidEnforce: TRUE adding new entry "cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config" modify complete add objectclass: top extensibleObject add cn: IPK11 Unique IDs add ipaUuidAttr: ipk11UniqueID add ipaUuidMagicRegen: autogenerate add ipaUuidFilter: (objectclass=ipk11Object) add ipaUuidScope: dc=redacted_domain,dc=com add ipaUuidEnforce: FALSE adding new entry "cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __config_uuid_module 0.03 sec 2022-12-17T23:51:00Z DEBUG [11/42]: configuring modrdn plugin 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/modrdn-conf.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA MODRDN add nsslapd-pluginpath: libipa_modrdn add nsslapd-plugininitfunc: ipamodrdn_init add nsslapd-plugintype: betxnpostoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipamodrdn_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA MODRDN plugin add nsslapd-plugin-depends-on-type: database add nsslapd-pluginPrecedence: 60 adding new entry "cn=IPA MODRDN,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp7oelnnv9', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=add objectclass: top extensibleObject add cn: Kerberos Principal Name add ipaModRDNsourceAttr: uid add ipaModRDNtargetAttr: krbPrincipalName add ipaModRDNsuffix: @REDACTED_DOMAIN.COM add ipaModRDNfilter: (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) add ipaModRDNscope: dc=redacted_domain,dc=com adding new entry "cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config" modify complete add objectclass: top extensibleObject add cn: Kerberos Canonical Name add ipaModRDNsourceAttr: uid add ipaModRDNtargetAttr: krbCanonicalName add ipaModRDNsuffix: @REDACTED_DOMAIN.COM add ipaModRDNfilter: (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) add ipaModRDNscope: dc=redacted_domain,dc=com adding new entry "cn=Kerberos Canonical Name,cn=IPA MODRDN,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __config_modrdn_module 0.03 sec 2022-12-17T23:51:00Z DEBUG [12/42]: configuring DNS plugin 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/ipa-dns-conf.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=add objectclass: top nsslapdPlugin extensibleObject add cn: IPA DNS add nsslapd-plugindescription: IPA DNS support plugin add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_dns add nsslapd-plugininitfunc: ipadns_init add nsslapd-pluginpath: libipa_dns.so add nsslapd-plugintype: preoperation add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-pluginversion: 1.0 add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA DNS,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __config_dns_module 0.01 sec 2022-12-17T23:51:00Z DEBUG [13/42]: enabling entryUSN plugin 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/entryusn.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=replace nsslapd-entryusn-global: on modifying entry "cn=config" modify complete replace nsslapd-entryusn-import-initval: next modifying entry "cn=config" modify complete replace nsslapd-pluginenabled: on modifying entry "cn=USN,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __enable_entryusn 0.02 sec 2022-12-17T23:51:00Z DEBUG [14/42]: configuring lockout plugin 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/lockout-conf.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Lockout add nsslapd-pluginpath: libipa_lockout add nsslapd-plugininitfunc: ipalockout_init add nsslapd-plugintype: object add nsslapd-pluginenabled: on add nsslapd-pluginid: ipalockout_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Lockout plugin add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA Lockout,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __config_lockout_module 0.01 sec 2022-12-17T23:51:00Z DEBUG [15/42]: configuring graceperiod plugin 2022-12-17T23:51:00Z DEBUG Created connection context.ldap2_139797528688784 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/graceperiod-conf.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Graceperiod add nsslapd-pluginpath: libipa_graceperiod add nsslapd-plugininitfunc: ipagraceperiod_init add nsslapd-plugintype: object add nsslapd-pluginenabled: on add nsslapd-pluginid: ipagraceperiod_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Graceperiod plugin add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA Graceperiod,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG step duration: dirsrv config_graceperiod_module 0.01 sec 2022-12-17T23:51:00Z DEBUG [16/42]: configuring topology plugin 2022-12-17T23:51:00Z DEBUG Starting external process 2022-12-17T23:51:00Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpa9yiit2k', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:00Z DEBUG Process finished, return code=0 2022-12-17T23:51:00Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: IPA Topology Configuration add nsslapd-pluginPath: libtopology add nsslapd-pluginInitfunc: ipa_topo_init add nsslapd-pluginType: object add nsslapd-pluginEnabled: on add nsslapd-topo-plugin-shared-config-base: cn=ipa,cn=etc,dc=redacted_domain,dc=com add nsslapd-topo-plugin-shared-replica-root: dc=redacted_domain,dc=com o=ipaca add nsslapd-topo-plugin-shared-binddngroup: cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com add nsslapd-topo-plugin-startup-delay: 20 add nsslapd-pluginId: none add nsslapd-plugin-depends-on-named: ldbm database Multisupplier Replication Plugin add nsslapd-pluginVersion: 1.0 add nsslapd-pluginVendor: none add nsslapd-pluginDescription: none adding new entry "cn=IPA Topology Configuration,cn=plugins,cn=config" modify complete 2022-12-17T23:51:00Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:00Z DEBUG step duration: dirsrv __config_topology_module 0.01 sec 2022-12-17T23:51:00Z DEBUG [17/42]: creating indices 2022-12-17T23:51:00Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:51:00Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:51:00Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:51:00Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:51:00Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:51:00Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:51:00Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:51:00Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:51:00Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:51:01Z DEBUG Created connection context.ldap2_139797518050128 2022-12-17T23:51:01Z DEBUG raw: idrange_show('REDACTED_DOMAIN.COM_id_range', version='2.251') 2022-12-17T23:51:01Z DEBUG idrange_show('REDACTED_DOMAIN.COM_id_range', rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:51:01Z DEBUG flushing ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:51:01Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:51:01Z DEBUG Parsing update file '/usr/share/ipa/updates/20-indices.update' 2022-12-17T23:51:01Z DEBUG New entry: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Initial value 2022-12-17T23:51:01Z DEBUG dn: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG only: set cn to 'accessRuleType', current value [] 2022-12-17T23:51:01Z DEBUG only: updated value ['accessRuleType'] 2022-12-17T23:51:01Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Final value after applying updates 2022-12-17T23:51:01Z DEBUG dn: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG cn: 2022-12-17T23:51:01Z DEBUG accessRuleType 2022-12-17T23:51:01Z DEBUG nsIndexType: 2022-12-17T23:51:01Z DEBUG eq 2022-12-17T23:51:01Z DEBUG New entry: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Initial value 2022-12-17T23:51:01Z DEBUG dn: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG only: set cn to 'altSecurityIdentities', current value [] 2022-12-17T23:51:01Z DEBUG only: updated value ['altSecurityIdentities'] 2022-12-17T23:51:01Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Final value after applying updates 2022-12-17T23:51:01Z DEBUG dn: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG cn: 2022-12-17T23:51:01Z DEBUG altSecurityIdentities 2022-12-17T23:51:01Z DEBUG nsIndexType: 2022-12-17T23:51:01Z DEBUG eq 2022-12-17T23:51:01Z DEBUG New entry: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Initial value 2022-12-17T23:51:01Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG only: set cn to 'automountkey', current value [] 2022-12-17T23:51:01Z DEBUG only: updated value ['automountkey'] 2022-12-17T23:51:01Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:01Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Final value after applying updates 2022-12-17T23:51:01Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG cn: 2022-12-17T23:51:01Z DEBUG automountkey 2022-12-17T23:51:01Z DEBUG nsIndexType: 2022-12-17T23:51:01Z DEBUG eq 2022-12-17T23:51:01Z DEBUG pres 2022-12-17T23:51:01Z DEBUG New entry: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Initial value 2022-12-17T23:51:01Z DEBUG dn: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG only: set cn to 'automountMapName', current value [] 2022-12-17T23:51:01Z DEBUG only: updated value ['automountMapName'] 2022-12-17T23:51:01Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Final value after applying updates 2022-12-17T23:51:01Z DEBUG dn: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG cn: 2022-12-17T23:51:01Z DEBUG automountMapName 2022-12-17T23:51:01Z DEBUG nsIndexType: 2022-12-17T23:51:01Z DEBUG eq 2022-12-17T23:51:01Z DEBUG New entry: cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Initial value 2022-12-17T23:51:01Z DEBUG dn: cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG only: set cn to 'carLicense', current value [] 2022-12-17T23:51:01Z DEBUG only: updated value ['carLicense'] 2022-12-17T23:51:01Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:01Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Final value after applying updates 2022-12-17T23:51:01Z DEBUG dn: cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG cn: 2022-12-17T23:51:01Z DEBUG carLicense 2022-12-17T23:51:01Z DEBUG nsIndexType: 2022-12-17T23:51:01Z DEBUG eq 2022-12-17T23:51:01Z DEBUG sub 2022-12-17T23:51:01Z DEBUG New entry: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Initial value 2022-12-17T23:51:01Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsindex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG only: set cn to 'description', current value [] 2022-12-17T23:51:01Z DEBUG only: updated value ['description'] 2022-12-17T23:51:01Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:01Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Final value after applying updates 2022-12-17T23:51:01Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsindex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG cn: 2022-12-17T23:51:01Z DEBUG description 2022-12-17T23:51:01Z DEBUG nsIndexType: 2022-12-17T23:51:01Z DEBUG eq 2022-12-17T23:51:01Z DEBUG sub 2022-12-17T23:51:01Z DEBUG New entry: cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Initial value 2022-12-17T23:51:01Z DEBUG dn: cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG only: set cn to 'displayname', current value [] 2022-12-17T23:51:01Z DEBUG only: updated value ['displayname'] 2022-12-17T23:51:01Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:01Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Final value after applying updates 2022-12-17T23:51:01Z DEBUG dn: cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG cn: 2022-12-17T23:51:01Z DEBUG displayname 2022-12-17T23:51:01Z DEBUG nsIndexType: 2022-12-17T23:51:01Z DEBUG eq 2022-12-17T23:51:01Z DEBUG sub 2022-12-17T23:51:01Z DEBUG New entry: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Initial value 2022-12-17T23:51:01Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG only: set cn to 'fqdn', current value [] 2022-12-17T23:51:01Z DEBUG only: updated value ['fqdn'] 2022-12-17T23:51:01Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:01Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:01Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Final value after applying updates 2022-12-17T23:51:01Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG cn: 2022-12-17T23:51:01Z DEBUG fqdn 2022-12-17T23:51:01Z DEBUG nsIndexType: 2022-12-17T23:51:01Z DEBUG eq 2022-12-17T23:51:01Z DEBUG pres 2022-12-17T23:51:01Z DEBUG sub 2022-12-17T23:51:01Z DEBUG New entry: cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Initial value 2022-12-17T23:51:01Z DEBUG dn: cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG only: set cn to 'gidnumber', current value [] 2022-12-17T23:51:01Z DEBUG only: updated value ['gidnumber'] 2022-12-17T23:51:01Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:01Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:01Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value [] 2022-12-17T23:51:01Z DEBUG add: updated value ['integerOrderingMatch'] 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Final value after applying updates 2022-12-17T23:51:01Z DEBUG dn: cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG objectClass: 2022-12-17T23:51:01Z DEBUG nsIndex 2022-12-17T23:51:01Z DEBUG top 2022-12-17T23:51:01Z DEBUG nsSystemIndex: 2022-12-17T23:51:01Z DEBUG false 2022-12-17T23:51:01Z DEBUG cn: 2022-12-17T23:51:01Z DEBUG gidnumber 2022-12-17T23:51:01Z DEBUG nsIndexType: 2022-12-17T23:51:01Z DEBUG eq 2022-12-17T23:51:01Z DEBUG nsMatchingRule: 2022-12-17T23:51:01Z DEBUG integerOrderingMatch 2022-12-17T23:51:01Z DEBUG New entry: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:01Z DEBUG --------------------------------------------- 2022-12-17T23:51:01Z DEBUG Initial value 2022-12-17T23:51:01Z DEBUG dn: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'hostCategory', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['hostCategory'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG hostCategory 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG New entry: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'idnsName', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['idnsName'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG idnsName 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaallowedtarget', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaallowedtarget'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaallowedtarget 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaAnchorUUID', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaAnchorUUID'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaAnchorUUID 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaassignedidview', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaassignedidview'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaassignedidview 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaCASubjectDN,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaCASubjectDN,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaCASubjectDN', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaCASubjectDN'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaCASubjectDN,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaCASubjectDN 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaCertmapData', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaCertmapData'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaCertmapData 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaConfigString', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaConfigString'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaConfigString 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaEnabledFlag', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaEnabledFlag'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaEnabledFlag 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaExternalMember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaExternalMember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaExternalMember', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaExternalMember'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaExternalMember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaExternalMember 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaIdpDevAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaIdpDevAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaIdpDevAuthEndpoint', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaIdpDevAuthEndpoint'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaIdpDevAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaIdpDevAuthEndpoint 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaIdpAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaIdpAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaIdpAuthEndpoint', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaIdpAuthEndpoint'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaIdpAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaIdpAuthEndpoint 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaIdpScope,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaIdpScope,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaIdpScope', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaIdpScope'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaIdpScope,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaIdpScope 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaIdpTokenEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaIdpTokenEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaIdpTokenEndpoint', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaIdpTokenEndpoint'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaIdpTokenEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaIdpTokenEndpoint 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaKrbAuthzData', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaKrbAuthzData'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaKrbAuthzData 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipakrbprincipalalias', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipakrbprincipalalias'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipakrbprincipalalias 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG New entry: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipalocation', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipalocation'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipalocation 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaMemberCa', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaMemberCa'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaMemberCa 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaMemberCertProfile', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaMemberCertProfile'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaMemberCertProfile 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaNTSecurityIdentifier,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaNTSecurityIdentifier,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaNTSecurityIdentifier', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaNTSecurityIdentifier'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaNTSecurityIdentifier,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaNTSecurityIdentifier 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaNTTrustPartner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaNTTrustPartner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaNTTrustPartner', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaNTTrustPartner'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['pres'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaNTTrustPartner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaNTTrustPartner 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaOriginalUid', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaOriginalUid'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaOriginalUid 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaOwner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaOwner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaOwner', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaOwner'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaOwner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaOwner 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG New entry: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipasudorunas', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipasudorunas'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipasudorunas 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaSubGidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaSubGidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaSubGidNumber', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaSubGidNumber'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['integerOrderingMatch'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaSubGidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaSubGidNumber 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG nsMatchingRule: 2022-12-17T23:51:02Z DEBUG integerOrderingMatch 2022-12-17T23:51:02Z DEBUG New entry: cn=ipaSubUidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipaSubUidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipaSubUidNumber', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipaSubUidNumber'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['integerOrderingMatch'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipaSubUidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipaSubUidNumber 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG nsMatchingRule: 2022-12-17T23:51:02Z DEBUG integerOrderingMatch 2022-12-17T23:51:02Z DEBUG New entry: cn=sudoorder,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=sudoorder,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'sudoorder', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['sudoorder'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['integerOrderingMatch'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=sudoorder,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG sudoorder 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG nsMatchingRule: 2022-12-17T23:51:02Z DEBUG integerOrderingMatch 2022-12-17T23:51:02Z DEBUG New entry: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipasudorunasgroup', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipasudorunasgroup'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipasudorunasgroup 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipatokenradiusconfiglink', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipatokenradiusconfiglink'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipatokenradiusconfiglink 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipauniqueid', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipauniqueid'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipauniqueid 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG New entry: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ipServicePort', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ipServicePort'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ipServicePort 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG New entry: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'krbCanonicalName', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['krbCanonicalName'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG krbCanonicalName 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=krbPasswordExpiration,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=krbPasswordExpiration,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'krbPasswordExpiration', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['krbPasswordExpiration'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=krbPasswordExpiration,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG krbPasswordExpiration 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG New entry: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'krbPrincipalName', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['krbPrincipalName'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG add: 'caseIgnoreIA5Match' to nsMatchingRule, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['caseIgnoreIA5Match'] 2022-12-17T23:51:02Z DEBUG add: 'caseExactIA5Match' to nsMatchingRule, current value ['caseIgnoreIA5Match'] 2022-12-17T23:51:02Z DEBUG add: updated value ['caseIgnoreIA5Match', 'caseExactIA5Match'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG krbPrincipalName 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG nsMatchingRule: 2022-12-17T23:51:02Z DEBUG caseIgnoreIA5Match 2022-12-17T23:51:02Z DEBUG caseExactIA5Match 2022-12-17T23:51:02Z DEBUG New entry: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsindex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'l', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['l'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsindex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG l 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'macAddress', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['macAddress'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG macAddress 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG New entry: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'managedby', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['managedby'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG managedby 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'manager', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['manager'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG manager 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG Updating existing entry: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG member 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG only: set cn to 'member', current value ['member'] 2022-12-17T23:51:02Z DEBUG only: updated value ['member'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG member 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG [(0, 'nsIndexType', ['pres', 'sub'])] 2022-12-17T23:51:02Z DEBUG Updated 1 2022-12-17T23:51:02Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'pres', b'sub'])] 2022-12-17T23:51:02Z DEBUG Done 2022-12-17T23:51:02Z DEBUG New entry: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'memberallowcmd', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['memberallowcmd'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG memberallowcmd 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'memberdenycmd', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['memberdenycmd'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG memberdenycmd 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'memberHost', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['memberHost'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG memberHost 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'memberManager', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['memberManager'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG memberManager 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG Updating existing entry: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG memberOf 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG only: set cn to 'memberOf', current value ['memberOf'] 2022-12-17T23:51:02Z DEBUG only: updated value ['memberOf'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG memberOf 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG [(0, 'nsIndexType', ['sub'])] 2022-12-17T23:51:02Z DEBUG Updated 1 2022-12-17T23:51:02Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'sub'])] 2022-12-17T23:51:02Z DEBUG Done 2022-12-17T23:51:02Z DEBUG New entry: cn=memberPrincipal,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=memberPrincipal,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'memberPrincipal', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['memberPrincipal'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=memberPrincipal,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG memberPrincipal 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG New entry: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'memberservice', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['memberservice'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG memberservice 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'memberuid', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['memberuid'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG memberuid 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG New entry: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'memberUser', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['memberUser'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG memberUser 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsindex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'nsHardwarePlatform', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['nsHardwarePlatform'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsindex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG nsHardwarePlatform 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsindex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'nsHostLocation', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['nsHostLocation'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsindex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG nsHostLocation 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsindex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'nsOsVersion', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['nsOsVersion'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsindex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG nsOsVersion 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG Updating existing entry: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ntUniqueId 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG only: set cn to 'ntUniqueId', current value ['ntUniqueId'] 2022-12-17T23:51:02Z DEBUG only: updated value ['ntUniqueId'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ntUniqueId 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG [(0, 'nsIndexType', ['pres'])] 2022-12-17T23:51:02Z DEBUG Updated 1 2022-12-17T23:51:02Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'pres'])] 2022-12-17T23:51:02Z DEBUG Done 2022-12-17T23:51:02Z DEBUG Updating existing entry: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ntUserDomainId 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG only: set cn to 'ntUserDomainId', current value ['ntUserDomainId'] 2022-12-17T23:51:02Z DEBUG only: updated value ['ntUserDomainId'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ntUserDomainId 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG [(0, 'nsIndexType', ['pres'])] 2022-12-17T23:51:02Z DEBUG Updated 1 2022-12-17T23:51:02Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'pres'])] 2022-12-17T23:51:02Z DEBUG Done 2022-12-17T23:51:02Z DEBUG New entry: cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'ou', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['ou'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG ou 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG Updating existing entry: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG owner 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG only: set cn to 'owner', current value ['owner'] 2022-12-17T23:51:02Z DEBUG only: updated value ['owner'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG owner 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG [(0, 'nsIndexType', ['sub'])] 2022-12-17T23:51:02Z DEBUG Updated 1 2022-12-17T23:51:02Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'sub'])] 2022-12-17T23:51:02Z DEBUG Done 2022-12-17T23:51:02Z DEBUG New entry: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'secretary', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['secretary'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG secretary 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG Updating existing entry: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG seeAlso 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG only: set cn to 'seealso', current value ['seeAlso'] 2022-12-17T23:51:02Z DEBUG only: updated value ['seealso'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG seealso 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG [(1, 'cn', ['seeAlso']), (0, 'cn', ['seealso']), (0, 'nsIndexType', ['sub'])] 2022-12-17T23:51:02Z DEBUG Updated 1 2022-12-17T23:51:02Z DEBUG update_entry modlist [(1, 'cn', [b'seeAlso']), (0, 'cn', [b'seealso']), (0, 'nsIndexType', [b'sub'])] 2022-12-17T23:51:02Z DEBUG Done 2022-12-17T23:51:02Z DEBUG New entry: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'serverhostname', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['serverhostname'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG serverhostname 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'sourcehost', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['sourcehost'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG sourcehost 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG New entry: cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'title', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['title'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG title 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG Updating existing entry: cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG uid 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG only: set cn to 'uid', current value ['uid'] 2022-12-17T23:51:02Z DEBUG only: updated value ['uid'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG uid 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG [(0, 'nsIndexType', ['sub'])] 2022-12-17T23:51:02Z DEBUG Updated 1 2022-12-17T23:51:02Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'sub'])] 2022-12-17T23:51:02Z DEBUG Done 2022-12-17T23:51:02Z DEBUG New entry: cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'uidnumber', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['uidnumber'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['integerOrderingMatch'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG uidnumber 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG nsMatchingRule: 2022-12-17T23:51:02Z DEBUG integerOrderingMatch 2022-12-17T23:51:02Z DEBUG Updating existing entry: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG uniquemember 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG only: set cn to 'uniquemember', current value ['uniquemember'] 2022-12-17T23:51:02Z DEBUG only: updated value ['uniquemember'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'sub' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG uniquemember 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG sub 2022-12-17T23:51:02Z DEBUG [(0, 'nsIndexType', ['sub'])] 2022-12-17T23:51:02Z DEBUG Updated 1 2022-12-17T23:51:02Z DEBUG update_entry modlist [(0, 'nsIndexType', [b'sub'])] 2022-12-17T23:51:02Z DEBUG Done 2022-12-17T23:51:02Z DEBUG New entry: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Initial value 2022-12-17T23:51:02Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG only: set cn to 'userCertificate', current value [] 2022-12-17T23:51:02Z DEBUG only: updated value ['userCertificate'] 2022-12-17T23:51:02Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq'] 2022-12-17T23:51:02Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:51:02Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:51:02Z DEBUG --------------------------------------------- 2022-12-17T23:51:02Z DEBUG Final value after applying updates 2022-12-17T23:51:02Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:51:02Z DEBUG objectClass: 2022-12-17T23:51:02Z DEBUG nsIndex 2022-12-17T23:51:02Z DEBUG top 2022-12-17T23:51:02Z DEBUG nsSystemIndex: 2022-12-17T23:51:02Z DEBUG false 2022-12-17T23:51:02Z DEBUG cn: 2022-12-17T23:51:02Z DEBUG userCertificate 2022-12-17T23:51:02Z DEBUG nsIndexType: 2022-12-17T23:51:02Z DEBUG eq 2022-12-17T23:51:02Z DEBUG pres 2022-12-17T23:51:02Z DEBUG Creating task cn=indextask_138906138624740960_12046,cn=index,cn=tasks,cn=config to index attributes: accessRuleType, altSecurityIdentities, automountMapName, automountkey, carLicense, description, displayname, fqdn, gidnumber, hostCategory, idnsName, ipServicePort, ipaAnchorUUID, ipaCASubjectDN, ipaCertmapData, ipaConfigString, ipaEnabledFlag, ipaExternalMember, ipaIdpAuthEndpoint, ipaIdpDevAuthEndpoint, ipaIdpScope, ipaIdpTokenEndpoint, ipaKrbAuthzData, ipaMemberCa, ipaMemberCertProfile, ipaNTSecurityIdentifier, ipaNTTrustPartner, ipaOriginalUid, ipaOwner, ipaSubGidNumber, ipaSubUidNumber, ipaallowedtarget, ipaassignedidview, ipakrbprincipalalias, ipalocation, ipasudorunas, ipasudorunasgroup, ipatokenradiusconfiglink, ipauniqueid, krbCanonicalName, krbPasswordExpiration, krbPrincipalName, l, macAddress, managedby, manager, member, memberHost, memberManager, memberOf, memberPrincipal, memberUser, memberallowcmd, memberdenycmd, memberservice, memberuid, nsHardwarePlatform, nsHostLocation, nsOsVersion, ntUniqueId, ntUserDomainId, ou, owner, secretary, seealso, serverhostname, sourcehost, sudoorder, title, uid, uidnumber, uniquemember, userCertificate 2022-12-17T23:51:03Z DEBUG Indexing finished 2022-12-17T23:51:03Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-indices.update 1.551 sec 2022-12-17T23:51:03Z DEBUG Destroyed connection context.ldap2_139797518050128 2022-12-17T23:51:03Z DEBUG step duration: dirsrv __create_indices 2.62 sec 2022-12-17T23:51:03Z DEBUG [18/42]: enabling referential integrity plugin 2022-12-17T23:51:03Z DEBUG Starting external process 2022-12-17T23:51:03Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/referint-conf.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:03Z DEBUG Process finished, return code=0 2022-12-17T23:51:03Z DEBUG stdout=replace nsslapd-pluginenabled: on modifying entry "cn=referential integrity postoperation,cn=plugins,cn=config" modify complete 2022-12-17T23:51:03Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:03Z DEBUG step duration: dirsrv __add_referint_module 0.02 sec 2022-12-17T23:51:03Z DEBUG [19/42]: configuring certmap.conf 2022-12-17T23:51:03Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:51:03Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:51:03Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:51:03Z DEBUG step duration: dirsrv __certmap_conf 0.00 sec 2022-12-17T23:51:03Z DEBUG [20/42]: configure new location for managed entries 2022-12-17T23:51:03Z DEBUG Starting external process 2022-12-17T23:51:03Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp_ylno03e', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:03Z DEBUG Process finished, return code=0 2022-12-17T23:51:03Z DEBUG stdout=add nsslapd-pluginConfigArea: cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com modifying entry "cn=Managed Entries,cn=plugins,cn=config" modify complete 2022-12-17T23:51:03Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:03Z DEBUG step duration: dirsrv __repoint_managed_entries 0.01 sec 2022-12-17T23:51:03Z DEBUG [21/42]: configure dirsrv ccache and keytab 2022-12-17T23:51:03Z DEBUG Starting external process 2022-12-17T23:51:03Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:51:03Z DEBUG Process finished, return code=0 2022-12-17T23:51:03Z DEBUG stdout= 2022-12-17T23:51:03Z DEBUG stderr= 2022-12-17T23:51:03Z DEBUG Starting external process 2022-12-17T23:51:03Z DEBUG args=['/sbin/restorecon', '/etc/systemd/system/dirsrv@REDACTED_DOMAIN-COM.service.d/ipa-env.conf'] 2022-12-17T23:51:03Z DEBUG Process finished, return code=0 2022-12-17T23:51:03Z DEBUG stdout= 2022-12-17T23:51:03Z DEBUG stderr= 2022-12-17T23:51:03Z DEBUG Starting external process 2022-12-17T23:51:03Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2022-12-17T23:51:03Z DEBUG Process finished, return code=0 2022-12-17T23:51:03Z DEBUG stdout= 2022-12-17T23:51:03Z DEBUG stderr= 2022-12-17T23:51:03Z DEBUG step duration: dirsrv configure_systemd_ipa_env 0.37 sec 2022-12-17T23:51:03Z DEBUG [22/42]: enabling SASL mapping fallback 2022-12-17T23:51:03Z DEBUG Starting external process 2022-12-17T23:51:03Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpv1b20kx2', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:03Z DEBUG Process finished, return code=0 2022-12-17T23:51:03Z DEBUG stdout=replace nsslapd-sasl-mapping-fallback: on modifying entry "cn=config" modify complete 2022-12-17T23:51:03Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:03Z DEBUG step duration: dirsrv __enable_sasl_mapping_fallback 0.02 sec 2022-12-17T23:51:03Z DEBUG [23/42]: restarting directory server 2022-12-17T23:51:03Z DEBUG Destroyed connection context.ldap2_139797528688784 2022-12-17T23:51:03Z DEBUG Starting external process 2022-12-17T23:51:03Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2022-12-17T23:51:04Z DEBUG Process finished, return code=0 2022-12-17T23:51:04Z DEBUG stdout= 2022-12-17T23:51:04Z DEBUG stderr= 2022-12-17T23:51:04Z DEBUG Starting external process 2022-12-17T23:51:04Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:51:07Z DEBUG Process finished, return code=0 2022-12-17T23:51:07Z DEBUG stdout= 2022-12-17T23:51:07Z DEBUG stderr= 2022-12-17T23:51:07Z DEBUG Starting external process 2022-12-17T23:51:07Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:51:07Z DEBUG Process finished, return code=0 2022-12-17T23:51:07Z DEBUG stdout=active 2022-12-17T23:51:07Z DEBUG stderr= 2022-12-17T23:51:07Z DEBUG wait_for_open_ports: localhost [389] timeout 120 2022-12-17T23:51:07Z DEBUG waiting for port: 389 2022-12-17T23:51:07Z DEBUG SUCCESS: port: 389 2022-12-17T23:51:07Z DEBUG Restart of dirsrv@REDACTED_DOMAIN-COM.service complete 2022-12-17T23:51:07Z DEBUG Starting external process 2022-12-17T23:51:07Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:51:07Z DEBUG Process finished, return code=0 2022-12-17T23:51:07Z DEBUG stdout=active 2022-12-17T23:51:07Z DEBUG stderr= 2022-12-17T23:51:07Z DEBUG Created connection context.ldap2_139797528688784 2022-12-17T23:51:07Z DEBUG step duration: dirsrv __restart_instance 3.56 sec 2022-12-17T23:51:07Z DEBUG [24/42]: adding sasl mappings to the directory 2022-12-17T23:51:07Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:51:07Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:51:07Z DEBUG step duration: dirsrv __configure_sasl_mappings 0.23 sec 2022-12-17T23:51:07Z DEBUG [25/42]: adding default layout 2022-12-17T23:51:07Z DEBUG Starting external process 2022-12-17T23:51:07Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp4dt8oeys', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:08Z DEBUG Process finished, return code=0 2022-12-17T23:51:08Z DEBUG stdout=add objectClass: top nsContainer add cn: accounts adding new entry "cn=accounts,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: users adding new entry "cn=users,cn=accounts,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: groups adding new entry "cn=groups,cn=accounts,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: services adding new entry "cn=services,cn=accounts,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: computers adding new entry "cn=computers,cn=accounts,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: hostgroups adding new entry "cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: ipservices adding new entry "cn=ipservices,cn=accounts,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer add cn: alt adding new entry "cn=alt,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer add cn: ng adding new entry "cn=ng,cn=alt,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer add cn: automount adding new entry "cn=automount,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer add cn: default adding new entry "cn=default,cn=automount,dc=redacted_domain,dc=com" modify complete add objectClass: automountMap add automountMapName: auto.master adding new entry "automountmapname=auto.master,cn=default,cn=automount,dc=redacted_domain,dc=com" modify complete add objectClass: automountMap add automountMapName: auto.direct adding new entry "automountmapname=auto.direct,cn=default,cn=automount,dc=redacted_domain,dc=com" modify complete add objectClass: automount add automountKey: /- add automountInformation: auto.direct add description: /- auto.direct adding new entry "description=/- auto.direct,automountmapname=auto.master,cn=default,cn=automount,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: hbac adding new entry "cn=hbac,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: hbacservices adding new entry "cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: hbacservicegroups adding new entry "cn=hbacservicegroups,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: sudo adding new entry "cn=sudo,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: sudocmds adding new entry "cn=sudocmds,cn=sudo,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: sudocmdgroups adding new entry "cn=sudocmdgroups,cn=sudo,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: sudorules adding new entry "cn=sudorules,cn=sudo,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: etc adding new entry "cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: locations adding new entry "cn=locations,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: sysaccounts adding new entry "cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: ipa adding new entry "cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: masters adding new entry "cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: replicas adding new entry "cn=replicas,cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: dna adding new entry "cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: posix-ids adding new entry "cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: subordinate-ids adding new entry "cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: ca_renewal adding new entry "cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: certificates adding new entry "cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: custodia adding new entry "cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: dogtag adding new entry "cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: s4u2proxy adding new entry "cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: ipaKrb5DelegationACL groupOfPrincipals top add cn: ipa-http-delegation add memberPrincipal: HTTP/master.redacted_domain.com@REDACTED_DOMAIN.COM add ipaAllowedTarget: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com adding new entry "cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: groupOfPrincipals top add cn: ipa-ldap-delegation-targets add memberPrincipal: ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM adding new entry "cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: groupOfPrincipals top add cn: ipa-cifs-delegation-targets adding new entry "cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: top person posixaccount krbprincipalaux krbticketpolicyaux inetuser ipaobject ipasshuser add uid: admin add krbPrincipalName: admin@REDACTED_DOMAIN.COM root@REDACTED_DOMAIN.COM add cn: Administrator add sn: Administrator add uidNumber: 1382800000 add gidNumber: 1382800000 add homeDirectory: /home/admin add loginShell: /bin/bash add gecos: Administrator add nsAccountLock: FALSE add ipaUniqueID: autogenerate adding new entry "uid=admin,cn=users,cn=accounts,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames posixgroup ipausergroup ipaobject add cn: admins add description: Account administrators group add gidNumber: 1382800000 add member: uid=admin,cn=users,cn=accounts,dc=redacted_domain,dc=com add nsAccountLock: FALSE add ipaUniqueID: autogenerate adding new entry "cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup ipausergroup ipaobject add description: Default group for all users add cn: ipausers add ipaUniqueID: autogenerate adding new entry "cn=ipausers,cn=groups,cn=accounts,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames posixgroup ipausergroup ipaobject add gidNumber: 1382800002 add description: Limited admins who can edit other users add cn: editors add ipaUniqueID: autogenerate adding new entry "cn=editors,cn=groups,cn=accounts,dc=redacted_domain,dc=com" modify complete add objectClass: top groupOfNames nestedGroup ipaobject ipahostgroup add description: IPA server hosts add cn: ipaservers add ipaUniqueID: autogenerate adding new entry "cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" modify complete add objectclass: ipahbacservice ipaobject add cn: sshd add description: sshd add ipauniqueid: autogenerate adding new entry "cn=sshd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectclass: ipahbacservice ipaobject add cn: ftp add description: ftp add ipauniqueid: autogenerate adding new entry "cn=ftp,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectclass: ipahbacservice ipaobject add cn: su add description: su add ipauniqueid: autogenerate adding new entry "cn=su,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectclass: ipahbacservice ipaobject add cn: login add description: login add ipauniqueid: autogenerate adding new entry "cn=login,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectclass: ipahbacservice ipaobject add cn: su-l add description: su with login shell add ipauniqueid: autogenerate adding new entry "cn=su-l,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectclass: ipahbacservice ipaobject add cn: sudo add description: sudo add ipauniqueid: autogenerate adding new entry "cn=sudo,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectclass: ipahbacservice ipaobject add cn: sudo-i add description: sudo-i add ipauniqueid: autogenerate adding new entry "cn=sudo-i,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectclass: ipahbacservice ipaobject add cn: systemd-user add description: pam_systemd and systemd user@.service add ipauniqueid: autogenerate adding new entry "cn=systemd-user,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectclass: ipahbacservice ipaobject add cn: gdm add description: gdm add ipauniqueid: autogenerate adding new entry "cn=gdm,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectclass: ipahbacservice ipaobject add cn: gdm-password add description: gdm-password add ipauniqueid: autogenerate adding new entry "cn=gdm-password,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectclass: ipahbacservice ipaobject add cn: kdm add description: kdm add ipauniqueid: autogenerate adding new entry "cn=kdm,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectClass: ipaobject ipahbacservicegroup nestedGroup groupOfNames top add cn: Sudo add ipauniqueid: autogenerate add description: Default group of Sudo related services add member: cn=sudo,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com cn=sudo-i,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com adding new entry "cn=Sudo,cn=hbacservicegroups,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top ipaGuiConfig ipaConfigObject add ipaUserSearchFields: uid,givenname,sn,telephonenumber,ou,title add ipaGroupSearchFields: cn,description add ipaSearchTimeLimit: 2 add ipaSearchRecordsLimit: 100 add ipaHomesRootDir: /home add ipaDefaultLoginShell: /bin/sh add ipaDefaultPrimaryGroup: ipausers add ipaMaxUsernameLength: 32 add ipaMaxHostnameLength: 64 add ipaPwdExpAdvNotify: 4 add ipaGroupObjectClasses: top groupofnames nestedgroup ipausergroup ipaobject add ipaUserObjectClasses: top person organizationalperson inetorgperson inetuser posixaccount krbprincipalaux krbticketpolicyaux ipaobject ipasshuser add ipaDefaultEmailDomain: redacted_domain.com add ipaMigrationEnabled: FALSE add ipaConfigString: AllowNThash KDC:Disable Last Success add ipaSELinuxUserMapOrder: guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 add ipaSELinuxUserMapDefault: unconfined_u:s0-s0:c0.c1023 adding new entry "cn=ipaConfig,cn=etc,dc=redacted_domain,dc=com" modify complete add objectclass: top nsContainer add cn: cosTemplates adding new entry "cn=cosTemplates,cn=accounts,dc=redacted_domain,dc=com" modify complete add description: Password Policy based on group membership add objectClass: top ldapsubentry cosSuperDefinition cosClassicDefinition add cosTemplateDn: cn=cosTemplates,cn=accounts,dc=redacted_domain,dc=com add cosAttribute: krbPwdPolicyReference override add cosSpecifier: memberOf adding new entry "cn=Password Policy,cn=accounts,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: selinux adding new entry "cn=selinux,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: usermap adding new entry "cn=usermap,cn=selinux,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: ranges adding new entry "cn=ranges,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: top ipaIDrange ipaDomainIDRange add cn: REDACTED_DOMAIN.COM_id_range add ipaBaseID: 1382800000 add ipaIDRangeSize: 200000 add ipaRangeType: ipa-local adding new entry "cn=REDACTED_DOMAIN.COM_id_range,cn=ranges,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: top ipaIDrange ipaTrustedADDomainRange add cn: REDACTED_DOMAIN.COM_subid_range add ipaBaseID: 2147483648 add ipaIDRangeSize: 2147352576 add ipaBaseRID: 2147283648 add ipaNTTrustedDomainSID: S-1-5-21-738065-838566-2100256441 add ipaRangeType: ipa-ad-trust adding new entry "cn=REDACTED_DOMAIN.COM_subid_range,cn=ranges,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: ca adding new entry "cn=ca,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: certprofiles adding new entry "cn=certprofiles,cn=ca,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: caacls adding new entry "cn=caacls,cn=ca,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: cas adding new entry "cn=cas,cn=ca,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:51:08Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:08Z DEBUG step duration: dirsrv __add_default_layout 0.60 sec 2022-12-17T23:51:08Z DEBUG [26/42]: adding delegation layout 2022-12-17T23:51:08Z DEBUG Starting external process 2022-12-17T23:51:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpg3kkkiea', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:08Z DEBUG Process finished, return code=0 2022-12-17T23:51:08Z DEBUG stdout=add objectClass: top nsContainer add cn: roles adding new entry "cn=roles,cn=accounts,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: pbac adding new entry "cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: privileges adding new entry "cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: permissions adding new entry "cn=permissions,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: helpdesk add description: Helpdesk adding new entry "cn=helpdesk,cn=roles,cn=accounts,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: User Administrators add description: User Administrators adding new entry "cn=User Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: Group Administrators add description: Group Administrators adding new entry "cn=Group Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: Host Administrators add description: Host Administrators adding new entry "cn=Host Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: Host Group Administrators add description: Host Group Administrators adding new entry "cn=Host Group Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: Delegation Administrator add description: Role administration adding new entry "cn=Delegation Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: DNS Administrators add description: DNS Administrators adding new entry "cn=DNS Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: DNS Servers add description: DNS Servers adding new entry "cn=DNS Servers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: Service Administrators add description: Service Administrators adding new entry "cn=Service Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: Automount Administrators add description: Automount Administrators adding new entry "cn=Automount Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: Netgroups Administrators add description: Netgroups Administrators adding new entry "cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: Certificate Administrators add description: Certificate Administrators adding new entry "cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: Replication Administrators add description: Replication Administrators add member: cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com adding new entry "cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: Host Enrollment add description: Host Enrollment adding new entry "cn=Host Enrollment,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: Stage User Administrators add description: Stage User Administrators adding new entry "cn=Stage User Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: Stage User Provisioning add description: Stage User Provisioning adding new entry "cn=Stage User Provisioning,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames ipapermission add cn: Add Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com adding new entry "cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames ipapermission add cn: Modify Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com adding new entry "cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames ipapermission add cn: Read Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com adding new entry "cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames ipapermission add cn: Remove Replication Agreements add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com adding new entry "cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames ipapermission add cn: Modify DNA Range add ipapermissiontype: SYSTEM add member: cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com adding new entry "cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer add cn: virtual operations adding new entry "cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames ipapermission add cn: Retrieve Certificates from the CA add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com adding new entry "cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) modifying entry "dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames ipapermission add cn: Request Certificate add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com adding new entry "cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) modifying entry "dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames ipapermission add cn: Request Certificates from a different host add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com adding new entry "cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) modifying entry "dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames ipapermission add cn: Get Certificates status from the CA add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com adding new entry "cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) modifying entry "dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames ipapermission add cn: Revoke Certificate add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com adding new entry "cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) modifying entry "dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames ipapermission add cn: Certificate Remove Hold add member: cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com adding new entry "cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com" modify complete add aci: (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) modifying entry "dc=redacted_domain,dc=com" modify complete add objectClass: top groupofnames nestedgroup add cn: External IdP server Administrators add description: External IdP server Administrators adding new entry "cn=External IdP server Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:51:08Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:08Z DEBUG step duration: dirsrv __add_delegation_layout 0.20 sec 2022-12-17T23:51:08Z DEBUG [27/42]: creating container for managed entries 2022-12-17T23:51:08Z DEBUG Starting external process 2022-12-17T23:51:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpyag2xify', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:08Z DEBUG Process finished, return code=0 2022-12-17T23:51:08Z DEBUG stdout=add objectClass: nsContainer top add cn: Managed Entries adding new entry "cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: Templates adding new entry "cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: Definitions adding new entry "cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:51:08Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:08Z DEBUG step duration: dirsrv __managed_entries 0.01 sec 2022-12-17T23:51:08Z DEBUG [28/42]: configuring user private groups 2022-12-17T23:51:08Z DEBUG Starting external process 2022-12-17T23:51:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp6oii1y_e', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:08Z DEBUG Process finished, return code=0 2022-12-17T23:51:08Z DEBUG stdout=add objectclass: mepTemplateEntry add cn: UPG Template add mepRDNAttr: cn add mepStaticAttr: objectclass: posixgroup objectclass: ipaobject ipaUniqueId: autogenerate add mepMappedAttr: cn: $uid gidNumber: $uidNumber description: User private group for $uid adding new entry "cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com" modify complete add objectclass: extensibleObject add cn: UPG Definition add originScope: cn=users,cn=accounts,dc=redacted_domain,dc=com add originFilter: (&(objectclass=posixAccount)(!(description=__no_upg__))) add managedBase: cn=groups,cn=accounts,dc=redacted_domain,dc=com add managedTemplate: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com adding new entry "cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:51:08Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:08Z DEBUG step duration: dirsrv __user_private_groups 0.01 sec 2022-12-17T23:51:08Z DEBUG [29/42]: configuring netgroups from hostgroups 2022-12-17T23:51:08Z DEBUG Starting external process 2022-12-17T23:51:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp8x9126eq', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:08Z DEBUG Process finished, return code=0 2022-12-17T23:51:08Z DEBUG stdout=add objectclass: mepTemplateEntry add cn: NGP HGP Template add mepRDNAttr: cn add mepStaticAttr: ipaUniqueId: autogenerate objectclass: ipanisnetgroup objectclass: ipaobject nisDomainName: redacted_domain.com add mepMappedAttr: cn: $cn memberHost: $dn description: ipaNetgroup $cn adding new entry "cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com" modify complete add objectclass: extensibleObject add cn: NGP Definition add originScope: cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com add originFilter: objectclass=ipahostgroup add managedBase: cn=ng,cn=alt,dc=redacted_domain,dc=com add managedTemplate: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com adding new entry "cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:51:08Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:08Z DEBUG step duration: dirsrv __host_nis_groups 0.01 sec 2022-12-17T23:51:08Z DEBUG [30/42]: creating default Sudo bind user 2022-12-17T23:51:08Z DEBUG Starting external process 2022-12-17T23:51:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpmoh1ond3', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:08Z DEBUG Process finished, return code=0 2022-12-17T23:51:08Z DEBUG stdout=add objectclass: account simplesecurityobject add uid: sudo add userPassword: XXXXXXXX add passwordExpirationTime: 20380119031407Z add nsIdleTimeout: 0 adding new entry "uid=sudo,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:51:08Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:08Z DEBUG step duration: dirsrv __add_sudo_binduser 0.02 sec 2022-12-17T23:51:08Z DEBUG [31/42]: creating default Auto Member layout 2022-12-17T23:51:08Z DEBUG Starting external process 2022-12-17T23:51:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp9i72lcvm', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:08Z DEBUG Process finished, return code=0 2022-12-17T23:51:08Z DEBUG stdout=add nsslapd-pluginConfigArea: cn=automember,cn=etc,dc=redacted_domain,dc=com modifying entry "cn=Auto Membership Plugin,cn=plugins,cn=config" modify complete add objectClass: top nsContainer add cn: automember adding new entry "cn=automember,cn=etc,dc=redacted_domain,dc=com" modify complete add objectclass: autoMemberDefinition add cn: Hostgroup add autoMemberScope: cn=computers,cn=accounts,dc=redacted_domain,dc=com add autoMemberFilter: objectclass=ipaHost add autoMemberGroupingAttr: member:dn adding new entry "cn=Hostgroup,cn=automember,cn=etc,dc=redacted_domain,dc=com" modify complete add objectclass: autoMemberDefinition add cn: Group add autoMemberScope: cn=users,cn=accounts,dc=redacted_domain,dc=com add autoMemberFilter: objectclass=posixAccount add autoMemberGroupingAttr: member:dn adding new entry "cn=Group,cn=automember,cn=etc,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:51:08Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:08Z DEBUG step duration: dirsrv __add_automember_config 0.02 sec 2022-12-17T23:51:08Z DEBUG [32/42]: adding range check plugin 2022-12-17T23:51:08Z DEBUG Starting external process 2022-12-17T23:51:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpsc21rx6u', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:08Z DEBUG Process finished, return code=0 2022-12-17T23:51:08Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Range-Check add nsslapd-pluginpath: libipa_range_check add nsslapd-plugininitfunc: ipa_range_check_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_range_check_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Range-Check plugin add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=redacted_domain,dc=com adding new entry "cn=IPA Range-Check,cn=plugins,cn=config" modify complete 2022-12-17T23:51:08Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:08Z DEBUG step duration: dirsrv __add_range_check_plugin 0.01 sec 2022-12-17T23:51:08Z DEBUG [33/42]: creating default HBAC rule allow_all 2022-12-17T23:51:08Z DEBUG Starting external process 2022-12-17T23:51:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpavpq0ya_', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:08Z DEBUG Process finished, return code=0 2022-12-17T23:51:08Z DEBUG stdout=add objectclass: ipaassociation ipahbacrule add cn: allow_all add accessruletype: allow add usercategory: all add hostcategory: all add servicecategory: all add ipaenabledflag: TRUE add description: Allow all users to access any host from any host add ipauniqueid: autogenerate adding new entry "ipauniqueid=autogenerate,cn=hbac,dc=redacted_domain,dc=com" modify complete add objectclass: ipaassociation ipahbacrule add cn: allow_systemd-user add accessruletype: allow add usercategory: all add hostcategory: all add memberService: cn=systemd-user,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com add ipaenabledflag: TRUE add description: Allow pam_systemd to run user@.service to create a system user session add ipauniqueid: autogenerate adding new entry "ipauniqueid=autogenerate,cn=hbac,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:51:08Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:08Z DEBUG step duration: dirsrv add_hbac 0.02 sec 2022-12-17T23:51:08Z DEBUG [34/42]: adding entries for topology management 2022-12-17T23:51:08Z DEBUG Starting external process 2022-12-17T23:51:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpltwdizhh', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:08Z DEBUG Process finished, return code=0 2022-12-17T23:51:08Z DEBUG stdout=add objectclass: top nsContainer add cn: topology adding new entry "cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete add objectclass: top iparepltopoconf add ipaReplTopoConfRoot: dc=redacted_domain,dc=com add nsDS5ReplicatedAttributeList: (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime add nsDS5ReplicatedAttributeListTotal: (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime add nsds5ReplicaStripAttrs: modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp add cn: domain adding new entry "cn=domain,cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:51:08Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:08Z DEBUG step duration: dirsrv __add_topology_entries 0.01 sec 2022-12-17T23:51:08Z DEBUG [35/42]: initializing group membership 2022-12-17T23:51:08Z DEBUG Starting external process 2022-12-17T23:51:08Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpac9b0qo7', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:08Z DEBUG Process finished, return code=0 2022-12-17T23:51:08Z DEBUG stdout=add objectClass: top extensibleObject add cn: IPA install add basedn: dc=redacted_domain,dc=com add filter: (objectclass=*) add ttl: 10 adding new entry "cn=IPA install 1671321036, cn=memberof task, cn=tasks, cn=config" modify complete 2022-12-17T23:51:08Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:08Z DEBUG Waiting for memberof task to complete. 2022-12-17T23:51:09Z DEBUG step duration: dirsrv init_memberof 1.01 sec 2022-12-17T23:51:09Z DEBUG [36/42]: adding master entry 2022-12-17T23:51:09Z DEBUG Starting external process 2022-12-17T23:51:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp07mnb9mz', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:09Z DEBUG Process finished, return code=0 2022-12-17T23:51:09Z DEBUG stdout=add objectclass: top nsContainer ipaReplTopoManagedServer ipaConfigObject ipaSupportedDomainLevelConfig add cn: master.redacted_domain.com add ipaReplTopoManagedSuffix: dc=redacted_domain,dc=com add ipaMinDomainLevel: 1 add ipaMaxDomainLevel: 1 adding new entry "cn=master.redacted_domain.com,cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:51:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:09Z DEBUG step duration: dirsrv __add_master_entry 0.01 sec 2022-12-17T23:51:09Z DEBUG [37/42]: initializing domain level 2022-12-17T23:51:09Z DEBUG Starting external process 2022-12-17T23:51:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmprsrp733l', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:09Z DEBUG Process finished, return code=0 2022-12-17T23:51:09Z DEBUG stdout=add objectClass: top nsContainer ipaDomainLevelConfig add ipaDomainLevel: 1 adding new entry "cn=Domain Level,cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:51:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:09Z DEBUG step duration: dirsrv __set_domain_level 0.01 sec 2022-12-17T23:51:09Z DEBUG [38/42]: configuring Posix uid/gid generation 2022-12-17T23:51:09Z DEBUG Starting external process 2022-12-17T23:51:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpiryk_qli', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:09Z DEBUG Process finished, return code=0 2022-12-17T23:51:09Z DEBUG stdout=add objectclass: top extensibleObject add cn: Posix IDs add dnaType: uidNumber gidNumber add dnaNextValue: 1382800000 add dnaMaxValue: 1382999999 add dnaMagicRegen: -1 add dnaFilter: (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) add dnaScope: dc=redacted_domain,dc=com add dnaThreshold: 500 add dnaSharedCfgDN: cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com add dnaExcludeScope: cn=provisioning,dc=redacted_domain,dc=com adding new entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete add objectclass: top extensibleObject add cn: Subordinate IDs add dnaType: ipasubuidnumber ipasubgidnumber add dnaNextValue: 2147483648 add dnaMaxValue: 4294836224 add dnaMagicRegen: -1 add dnaFilter: (objectClass=ipaSubordinateId) add dnaScope: dc=redacted_domain,dc=com add dnaThreshold: 500 add dnaSharedCfgDN: cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com add dnaExcludeScope: cn=provisioning,dc=redacted_domain,dc=com add dnaInterval: 65536 adding new entry "cn=Subordinate IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete replace nsslapd-pluginEnabled: on modifying entry "cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete 2022-12-17T23:51:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:09Z DEBUG step duration: dirsrv __config_uidgid_gen 0.02 sec 2022-12-17T23:51:09Z DEBUG [39/42]: adding replication acis 2022-12-17T23:51:09Z DEBUG Starting external process 2022-12-17T23:51:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpt2n2xim4', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:09Z DEBUG Process finished, return code=0 2022-12-17T23:51:09Z DEBUG stdout=add aci: (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) modifying entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete add aci: (targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) modifying entry "cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add aci: (targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) modifying entry "cn=tasks,cn=config" modify complete 2022-12-17T23:51:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:09Z DEBUG step duration: dirsrv __add_replication_acis 0.04 sec 2022-12-17T23:51:09Z DEBUG [40/42]: activating sidgen plugin 2022-12-17T23:51:09Z DEBUG Starting external process 2022-12-17T23:51:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpotwvt1qp', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:09Z DEBUG Process finished, return code=0 2022-12-17T23:51:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA SIDGEN add nsslapd-pluginpath: libipa_sidgen add nsslapd-plugininitfunc: ipa_sidgen_init add nsslapd-plugintype: postoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_sidgen_postop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA SIDGEN post operation add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=redacted_domain,dc=com adding new entry "cn=IPA SIDGEN,cn=plugins,cn=config" modify complete 2022-12-17T23:51:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:09Z DEBUG step duration: dirsrv _add_sidgen_plugin 0.01 sec 2022-12-17T23:51:09Z DEBUG [41/42]: activating extdom plugin 2022-12-17T23:51:09Z DEBUG Starting external process 2022-12-17T23:51:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp0rmkf2zb', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:09Z DEBUG Process finished, return code=0 2022-12-17T23:51:09Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_extdom_extop add nsslapd-pluginpath: libipa_extdom_extop add nsslapd-plugininitfunc: ipa_extdom_init add nsslapd-plugintype: extendedop add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_extdom_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Support resolving IDs in trusted domains to names and back add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=redacted_domain,dc=com adding new entry "cn=ipa_extdom_extop,cn=plugins,cn=config" modify complete 2022-12-17T23:51:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:09Z DEBUG step duration: dirsrv _add_extdom_plugin 0.03 sec 2022-12-17T23:51:09Z DEBUG [42/42]: configuring directory to start on boot 2022-12-17T23:51:09Z DEBUG Starting external process 2022-12-17T23:51:09Z DEBUG args=['/bin/systemctl', 'is-enabled', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:51:09Z DEBUG Process finished, return code=0 2022-12-17T23:51:09Z DEBUG stdout=enabled 2022-12-17T23:51:09Z DEBUG stderr= 2022-12-17T23:51:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:09Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:09Z DEBUG Starting external process 2022-12-17T23:51:09Z DEBUG args=['/bin/systemctl', 'disable', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:51:10Z DEBUG Process finished, return code=0 2022-12-17T23:51:10Z DEBUG stdout= 2022-12-17T23:51:10Z DEBUG stderr=Removed "/etc/systemd/system/multi-user.target.wants/dirsrv@REDACTED_DOMAIN-COM.service". Removed "/etc/systemd/system/dirsrv.target.wants/dirsrv@REDACTED_DOMAIN-COM.service". 2022-12-17T23:51:10Z DEBUG step duration: dirsrv __enable 0.40 sec 2022-12-17T23:51:10Z DEBUG Done configuring directory server (dirsrv). 2022-12-17T23:51:10Z DEBUG service duration: dirsrv 33.60 sec 2022-12-17T23:51:12Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:51:12Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:51:12Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:51:12Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:51:12Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:51:12Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:51:12Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:51:12Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:51:12Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:51:12Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:51:13Z DEBUG Created connection context.ldap2_140157314091216 2022-12-17T23:51:13Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:13Z DEBUG Starting external process 2022-12-17T23:51:13Z DEBUG args=['/bin/keyctl', 'get_persistent', '@s', '0'] 2022-12-17T23:51:13Z DEBUG Process finished, return code=0 2022-12-17T23:51:13Z DEBUG stdout=365356300 2022-12-17T23:51:13Z DEBUG stderr= 2022-12-17T23:51:13Z DEBUG Enabling persistent keyring CCACHE 2022-12-17T23:51:13Z DEBUG Starting external process 2022-12-17T23:51:13Z DEBUG args=['/bin/systemctl', 'is-active', 'krb5kdc.service'] 2022-12-17T23:51:13Z DEBUG Process finished, return code=3 2022-12-17T23:51:13Z DEBUG stdout=inactive 2022-12-17T23:51:13Z DEBUG stderr= 2022-12-17T23:51:13Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:13Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:13Z DEBUG Starting external process 2022-12-17T23:51:13Z DEBUG args=['/bin/systemctl', 'stop', 'krb5kdc.service'] 2022-12-17T23:51:13Z DEBUG Process finished, return code=0 2022-12-17T23:51:13Z DEBUG stdout= 2022-12-17T23:51:13Z DEBUG stderr= 2022-12-17T23:51:13Z DEBUG Stop of krb5kdc.service complete 2022-12-17T23:51:13Z DEBUG Configuring Kerberos KDC (krb5kdc) 2022-12-17T23:51:13Z DEBUG [1/10]: adding kerberos container to the directory 2022-12-17T23:51:13Z DEBUG Starting external process 2022-12-17T23:51:13Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp1jkq0qbm', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:13Z DEBUG Process finished, return code=0 2022-12-17T23:51:13Z DEBUG stdout=add objectClass: krbContainer top add cn: kerberos adding new entry "cn=kerberos,dc=redacted_domain,dc=com" modify complete add cn: REDACTED_DOMAIN.COM add objectClass: top krbrealmcontainer krbticketpolicyaux add krbSubTrees: dc=redacted_domain,dc=com add krbSearchScope: 2 add krbSupportedEncSaltTypes: aes256-cts:normal aes256-cts:special aes128-cts:normal aes128-cts:special aes128-sha2:normal aes128-sha2:special aes256-sha2:normal aes256-sha2:special camellia128-cts-cmac:normal camellia128-cts-cmac:special camellia256-cts-cmac:normal camellia256-cts-cmac:special add krbMaxTicketLife: 86400 add krbMaxRenewableAge: 604800 add krbDefaultEncSaltTypes: aes256-sha2:special aes128-sha2:special aes256-cts:special aes128-cts:special adding new entry "cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com" modify complete add objectClass: top nsContainer krbPwdPolicy ipaPwdPolicy add krbMinPwdLife: 3600 add krbPwdMinDiffChars: 0 add krbPwdMinLength: 8 add krbPwdHistoryLength: 0 add krbMaxPwdLife: 7776000 add krbPwdMaxFailure: 6 add krbPwdFailureCountInterval: 60 add krbPwdLockoutDuration: 600 add passwordGraceLimit: -1 adding new entry "cn=global_policy,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:51:13Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:13Z DEBUG step duration: krb5kdc __add_krb_container 0.08 sec 2022-12-17T23:51:13Z DEBUG [2/10]: configuring KDC 2022-12-17T23:51:13Z DEBUG Backing up system configuration file '/var/kerberos/krb5kdc/kdc.conf' 2022-12-17T23:51:13Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:51:13Z DEBUG Backing up system configuration file '/etc/krb5.conf' 2022-12-17T23:51:13Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:51:13Z DEBUG Backing up system configuration file '/etc/krb5.conf.d/freeipa-server' 2022-12-17T23:51:13Z DEBUG -> Not backing up - '/etc/krb5.conf.d/freeipa-server' doesn't exist 2022-12-17T23:51:13Z DEBUG Backing up system configuration file '/etc/krb5.conf.d/freeipa' 2022-12-17T23:51:13Z DEBUG -> Not backing up - '/etc/krb5.conf.d/freeipa' doesn't exist 2022-12-17T23:51:13Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb5.ini' 2022-12-17T23:51:13Z DEBUG -> Not backing up - '/usr/share/ipa/html/krb5.ini' doesn't exist 2022-12-17T23:51:13Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb.con' 2022-12-17T23:51:13Z DEBUG -> Not backing up - '/usr/share/ipa/html/krb.con' doesn't exist 2022-12-17T23:51:13Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krbrealm.con' 2022-12-17T23:51:13Z DEBUG -> Not backing up - '/usr/share/ipa/html/krbrealm.con' doesn't exist 2022-12-17T23:51:13Z DEBUG Starting external process 2022-12-17T23:51:13Z DEBUG args=['/usr/bin/klist', '-V'] 2022-12-17T23:51:13Z DEBUG Process finished, return code=0 2022-12-17T23:51:13Z DEBUG stdout=Kerberos 5 version 1.19.2 2022-12-17T23:51:13Z DEBUG stderr= 2022-12-17T23:51:13Z DEBUG Backing up system configuration file '/etc/sysconfig/krb5kdc' 2022-12-17T23:51:13Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:51:13Z DEBUG Starting external process 2022-12-17T23:51:13Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:51:13Z DEBUG Process finished, return code=0 2022-12-17T23:51:13Z DEBUG stdout= 2022-12-17T23:51:13Z DEBUG stderr= 2022-12-17T23:51:13Z DEBUG Starting external process 2022-12-17T23:51:13Z DEBUG args=['/sbin/restorecon', '/etc/sysconfig/krb5kdc'] 2022-12-17T23:51:13Z DEBUG Process finished, return code=0 2022-12-17T23:51:13Z DEBUG stdout= 2022-12-17T23:51:13Z DEBUG stderr= 2022-12-17T23:51:13Z DEBUG step duration: krb5kdc __configure_instance 0.06 sec 2022-12-17T23:51:13Z DEBUG [3/10]: initialize kerberos container 2022-12-17T23:51:13Z DEBUG Starting external process 2022-12-17T23:51:13Z DEBUG args=['kdb5_util', 'create', '-s', '-r', 'REDACTED_DOMAIN.COM', '-x', 'ipa-setup-override-restrictions'] 2022-12-17T23:51:13Z DEBUG Process finished, return code=0 2022-12-17T23:51:13Z DEBUG stdout=Loading random data Initializing database '/var/kerberos/krb5kdc/principal' for realm 'REDACTED_DOMAIN.COM', master key name 'K/M@REDACTED_DOMAIN.COM' You will be prompted for the database Master Password. It is important that you NOT FORGET this password. Enter KDC database master key: Re-enter KDC database master key to verify: 2022-12-17T23:51:13Z DEBUG stderr= 2022-12-17T23:51:13Z DEBUG step duration: krb5kdc __init_ipa_kdb 0.41 sec 2022-12-17T23:51:13Z DEBUG [4/10]: adding default ACIs 2022-12-17T23:51:13Z DEBUG Starting external process 2022-12-17T23:51:13Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp86rojbd0', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:13Z DEBUG Process finished, return code=0 2022-12-17T23:51:13Z DEBUG stdout=add aci: (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) modifying entry "dc=redacted_domain,dc=com" modify complete add aci: (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) modifying entry "dc=redacted_domain,dc=com" modify complete add aci: (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) modifying entry "cn=etc,dc=redacted_domain,dc=com" modify complete add aci: (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) modifying entry "cn=ipa,cn=etc,dc=redacted_domain,dc=com" modify complete add aci: (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) modifying entry "cn=accounts,dc=redacted_domain,dc=com" modify complete add aci: (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) modifying entry "cn=services,cn=accounts,dc=redacted_domain,dc=com" modify complete add aci: (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) modifying entry "cn=services,cn=accounts,dc=redacted_domain,dc=com" modify complete add aci: (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) modifying entry "cn=computers,cn=accounts,dc=redacted_domain,dc=com" modify complete add aci: (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) modifying entry "cn=computers,cn=accounts,dc=redacted_domain,dc=com" modify complete add aci: (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) modifying entry "cn=computers,cn=accounts,dc=redacted_domain,dc=com" modify complete add aci: (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) modifying entry "cn=groups,cn=accounts,dc=redacted_domain,dc=com" modify complete add aci: (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) modifying entry "cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" modify complete add aci: (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) modifying entry "cn=accounts,dc=redacted_domain,dc=com" modify complete add aci: (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) modifying entry "dc=redacted_domain,dc=com" modify complete 2022-12-17T23:51:13Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:13Z DEBUG step duration: krb5kdc __add_default_acis 0.03 sec 2022-12-17T23:51:13Z DEBUG [5/10]: creating a keytab for the directory 2022-12-17T23:51:13Z DEBUG Starting external process 2022-12-17T23:51:13Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM', '-x', 'ipa-setup-override-restrictions'] 2022-12-17T23:51:14Z DEBUG Process finished, return code=0 2022-12-17T23:51:14Z DEBUG stdout=Authenticating as principal root/admin@REDACTED_DOMAIN.COM with password. Principal "ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM" created. 2022-12-17T23:51:14Z DEBUG stderr=No policy specified for ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM; defaulting to no policy 2022-12-17T23:51:14Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:51:14Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:51:14Z DEBUG Backing up system configuration file '/etc/dirsrv/ds.keytab' 2022-12-17T23:51:14Z DEBUG -> Not backing up - '/etc/dirsrv/ds.keytab' doesn't exist 2022-12-17T23:51:14Z DEBUG Starting external process 2022-12-17T23:51:14Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/dirsrv/ds.keytab ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM', '-x', 'ipa-setup-override-restrictions'] 2022-12-17T23:51:14Z DEBUG Process finished, return code=0 2022-12-17T23:51:14Z DEBUG stdout=Authenticating as principal root/admin@REDACTED_DOMAIN.COM with password. Entry for principal ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/dirsrv/ds.keytab. Entry for principal ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/dirsrv/ds.keytab. 2022-12-17T23:51:14Z DEBUG stderr= 2022-12-17T23:51:14Z DEBUG step duration: krb5kdc __create_ds_keytab 1.16 sec 2022-12-17T23:51:14Z DEBUG [6/10]: creating a keytab for the machine 2022-12-17T23:51:14Z DEBUG Starting external process 2022-12-17T23:51:14Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey host/master.redacted_domain.com@REDACTED_DOMAIN.COM', '-x', 'ipa-setup-override-restrictions'] 2022-12-17T23:51:15Z DEBUG Process finished, return code=0 2022-12-17T23:51:15Z DEBUG stdout=Authenticating as principal root/admin@REDACTED_DOMAIN.COM with password. Principal "host/master.redacted_domain.com@REDACTED_DOMAIN.COM" created. 2022-12-17T23:51:15Z DEBUG stderr=No policy specified for host/master.redacted_domain.com@REDACTED_DOMAIN.COM; defaulting to no policy 2022-12-17T23:51:15Z DEBUG Backing up system configuration file '/etc/krb5.keytab' 2022-12-17T23:51:15Z DEBUG -> Not backing up - '/etc/krb5.keytab' doesn't exist 2022-12-17T23:51:15Z DEBUG Starting external process 2022-12-17T23:51:15Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/krb5.keytab host/master.redacted_domain.com@REDACTED_DOMAIN.COM', '-x', 'ipa-setup-override-restrictions'] 2022-12-17T23:51:15Z DEBUG Process finished, return code=0 2022-12-17T23:51:15Z DEBUG stdout=Authenticating as principal root/admin@REDACTED_DOMAIN.COM with password. Entry for principal host/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/krb5.keytab. Entry for principal host/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/krb5.keytab. 2022-12-17T23:51:15Z DEBUG stderr= 2022-12-17T23:51:15Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:51:15Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:51:15Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:51:15Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:51:15Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:51:15Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:51:15Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:51:15Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:51:15Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:51:16Z DEBUG Created connection context.ldap2_140157302919952 2022-12-17T23:51:16Z DEBUG raw: idrange_show('REDACTED_DOMAIN.COM_id_range', version='2.251') 2022-12-17T23:51:16Z DEBUG idrange_show('REDACTED_DOMAIN.COM_id_range', rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:51:16Z DEBUG flushing ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:51:16Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:51:16Z DEBUG Parsing update file '/usr/share/ipa/updates/20-ipaservers_hostgroup.update' 2022-12-17T23:51:16Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:51:16Z DEBUG --------------------------------------------- 2022-12-17T23:51:16Z DEBUG Initial value 2022-12-17T23:51:16Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:51:16Z DEBUG objectClass: 2022-12-17T23:51:16Z DEBUG top 2022-12-17T23:51:16Z DEBUG groupOfNames 2022-12-17T23:51:16Z DEBUG nestedGroup 2022-12-17T23:51:16Z DEBUG ipaobject 2022-12-17T23:51:16Z DEBUG ipahostgroup 2022-12-17T23:51:16Z DEBUG description: 2022-12-17T23:51:16Z DEBUG IPA server hosts 2022-12-17T23:51:16Z DEBUG cn: 2022-12-17T23:51:16Z DEBUG ipaservers 2022-12-17T23:51:16Z DEBUG ipaUniqueID: 2022-12-17T23:51:16Z DEBUG ad2291bc-7e65-11ed-9994-525400000010 2022-12-17T23:51:16Z DEBUG --------------------------------------------- 2022-12-17T23:51:16Z DEBUG Final value after applying updates 2022-12-17T23:51:16Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:51:16Z DEBUG objectClass: 2022-12-17T23:51:16Z DEBUG top 2022-12-17T23:51:16Z DEBUG groupOfNames 2022-12-17T23:51:16Z DEBUG nestedGroup 2022-12-17T23:51:16Z DEBUG ipaobject 2022-12-17T23:51:16Z DEBUG ipahostgroup 2022-12-17T23:51:16Z DEBUG description: 2022-12-17T23:51:16Z DEBUG IPA server hosts 2022-12-17T23:51:16Z DEBUG cn: 2022-12-17T23:51:16Z DEBUG ipaservers 2022-12-17T23:51:16Z DEBUG ipaUniqueID: 2022-12-17T23:51:16Z DEBUG ad2291bc-7e65-11ed-9994-525400000010 2022-12-17T23:51:16Z DEBUG [] 2022-12-17T23:51:16Z DEBUG Updated 0 2022-12-17T23:51:16Z DEBUG Done 2022-12-17T23:51:16Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:51:16Z DEBUG --------------------------------------------- 2022-12-17T23:51:16Z DEBUG Initial value 2022-12-17T23:51:16Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:51:16Z DEBUG objectClass: 2022-12-17T23:51:16Z DEBUG top 2022-12-17T23:51:16Z DEBUG groupOfNames 2022-12-17T23:51:16Z DEBUG nestedGroup 2022-12-17T23:51:16Z DEBUG ipaobject 2022-12-17T23:51:16Z DEBUG ipahostgroup 2022-12-17T23:51:16Z DEBUG description: 2022-12-17T23:51:16Z DEBUG IPA server hosts 2022-12-17T23:51:16Z DEBUG cn: 2022-12-17T23:51:16Z DEBUG ipaservers 2022-12-17T23:51:16Z DEBUG ipaUniqueID: 2022-12-17T23:51:16Z DEBUG ad2291bc-7e65-11ed-9994-525400000010 2022-12-17T23:51:16Z DEBUG add: 'fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:51:16Z DEBUG add: updated value ['fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:51:16Z DEBUG --------------------------------------------- 2022-12-17T23:51:16Z DEBUG Final value after applying updates 2022-12-17T23:51:16Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:51:16Z DEBUG objectClass: 2022-12-17T23:51:16Z DEBUG top 2022-12-17T23:51:16Z DEBUG groupOfNames 2022-12-17T23:51:16Z DEBUG nestedGroup 2022-12-17T23:51:16Z DEBUG ipaobject 2022-12-17T23:51:16Z DEBUG ipahostgroup 2022-12-17T23:51:16Z DEBUG description: 2022-12-17T23:51:16Z DEBUG IPA server hosts 2022-12-17T23:51:16Z DEBUG cn: 2022-12-17T23:51:16Z DEBUG ipaservers 2022-12-17T23:51:16Z DEBUG ipaUniqueID: 2022-12-17T23:51:16Z DEBUG ad2291bc-7e65-11ed-9994-525400000010 2022-12-17T23:51:16Z DEBUG member: 2022-12-17T23:51:16Z DEBUG fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:51:16Z DEBUG [(2, 'member', ['fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:51:16Z DEBUG Updated 1 2022-12-17T23:51:16Z DEBUG update_entry modlist [(2, 'member', [b'fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:51:16Z DEBUG Done 2022-12-17T23:51:16Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-ipaservers_hostgroup.update 0.012 sec 2022-12-17T23:51:16Z DEBUG Destroyed connection context.ldap2_140157302919952 2022-12-17T23:51:16Z DEBUG step duration: krb5kdc __create_host_keytab 1.48 sec 2022-12-17T23:51:16Z DEBUG [7/10]: adding the password extension to the directory 2022-12-17T23:51:16Z DEBUG Starting external process 2022-12-17T23:51:16Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpizu93qis', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:16Z DEBUG Process finished, return code=0 2022-12-17T23:51:16Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_pwd_extop add nsslapd-pluginpath: libipa_pwd_extop add nsslapd-plugininitfunc: ipapwd_init add nsslapd-plugintype: extendedop add nsslapd-pluginbetxn: on add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_pwd_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Support saving passwords in multiple formats for different consumers (krb5, samba, freeradius, etc.) add nsslapd-plugin-depends-on-type: database add nsslapd-realmTree: dc=redacted_domain,dc=com adding new entry "cn=ipa_pwd_extop,cn=plugins,cn=config" modify complete 2022-12-17T23:51:16Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:16Z DEBUG step duration: krb5kdc __add_pwd_extop_module 0.02 sec 2022-12-17T23:51:16Z DEBUG [8/10]: creating anonymous principal 2022-12-17T23:51:16Z DEBUG Starting external process 2022-12-17T23:51:16Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey WELLKNOWN/ANONYMOUS@REDACTED_DOMAIN.COM', '-x', 'ipa-setup-override-restrictions'] 2022-12-17T23:51:16Z DEBUG Process finished, return code=0 2022-12-17T23:51:16Z DEBUG stdout=Authenticating as principal root/admin@REDACTED_DOMAIN.COM with password. Principal "WELLKNOWN/ANONYMOUS@REDACTED_DOMAIN.COM" created. 2022-12-17T23:51:16Z DEBUG stderr=No policy specified for WELLKNOWN/ANONYMOUS@REDACTED_DOMAIN.COM; defaulting to no policy 2022-12-17T23:51:16Z DEBUG Starting external process 2022-12-17T23:51:16Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpym_wlthn', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:51:16Z DEBUG Process finished, return code=0 2022-12-17T23:51:16Z DEBUG stdout=add objectclass: ipaAllowedOperations add aci: (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) add ipaAllowedToPerform;read_keys: cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com modifying entry "krbPrincipalName=WELLKNOWN/ANONYMOUS@REDACTED_DOMAIN.COM,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:51:16Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:51:16Z DEBUG step duration: krb5kdc add_anonymous_principal 0.15 sec 2022-12-17T23:51:16Z DEBUG [9/10]: starting the KDC 2022-12-17T23:51:16Z DEBUG Starting external process 2022-12-17T23:51:16Z DEBUG args=['/bin/systemctl', 'start', 'krb5kdc.service'] 2022-12-17T23:51:16Z DEBUG Process finished, return code=0 2022-12-17T23:51:16Z DEBUG stdout= 2022-12-17T23:51:16Z DEBUG stderr= 2022-12-17T23:51:16Z DEBUG Starting external process 2022-12-17T23:51:16Z DEBUG args=['/bin/systemctl', 'is-active', 'krb5kdc.service'] 2022-12-17T23:51:16Z DEBUG Process finished, return code=0 2022-12-17T23:51:16Z DEBUG stdout=active 2022-12-17T23:51:16Z DEBUG stderr= 2022-12-17T23:51:16Z DEBUG Start of krb5kdc.service complete 2022-12-17T23:51:16Z DEBUG step duration: krb5kdc __start_instance 0.10 sec 2022-12-17T23:51:16Z DEBUG [10/10]: configuring KDC to start on boot 2022-12-17T23:51:16Z DEBUG Starting external process 2022-12-17T23:51:16Z DEBUG args=['/bin/systemctl', 'is-enabled', 'krb5kdc.service'] 2022-12-17T23:51:16Z DEBUG Process finished, return code=1 2022-12-17T23:51:16Z DEBUG stdout=disabled 2022-12-17T23:51:16Z DEBUG stderr= 2022-12-17T23:51:16Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:16Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:16Z DEBUG Starting external process 2022-12-17T23:51:16Z DEBUG args=['/bin/systemctl', 'unmask', 'krb5kdc.service'] 2022-12-17T23:51:17Z DEBUG Process finished, return code=0 2022-12-17T23:51:17Z DEBUG stdout= 2022-12-17T23:51:17Z DEBUG stderr= 2022-12-17T23:51:17Z DEBUG Starting external process 2022-12-17T23:51:17Z DEBUG args=['/bin/systemctl', 'disable', 'krb5kdc.service'] 2022-12-17T23:51:17Z DEBUG Process finished, return code=0 2022-12-17T23:51:17Z DEBUG stdout= 2022-12-17T23:51:17Z DEBUG stderr= 2022-12-17T23:51:17Z DEBUG step duration: krb5kdc __enable 0.73 sec 2022-12-17T23:51:17Z DEBUG Done configuring Kerberos KDC (krb5kdc). 2022-12-17T23:51:17Z DEBUG service duration: krb5kdc 4.22 sec 2022-12-17T23:51:17Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:17Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:51:17Z DEBUG Configuring kadmin 2022-12-17T23:51:17Z DEBUG [1/2]: starting kadmin 2022-12-17T23:51:17Z DEBUG Starting external process 2022-12-17T23:51:17Z DEBUG args=['/bin/systemctl', 'is-active', 'kadmin.service'] 2022-12-17T23:51:17Z DEBUG Process finished, return code=3 2022-12-17T23:51:17Z DEBUG stdout=inactive 2022-12-17T23:51:17Z DEBUG stderr= 2022-12-17T23:51:17Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:17Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:17Z DEBUG Starting external process 2022-12-17T23:51:17Z DEBUG args=['/bin/systemctl', 'restart', 'kadmin.service'] 2022-12-17T23:51:17Z DEBUG Process finished, return code=0 2022-12-17T23:51:17Z DEBUG stdout= 2022-12-17T23:51:17Z DEBUG stderr= 2022-12-17T23:51:17Z DEBUG Starting external process 2022-12-17T23:51:17Z DEBUG args=['/bin/systemctl', 'is-active', 'kadmin.service'] 2022-12-17T23:51:17Z DEBUG Process finished, return code=0 2022-12-17T23:51:17Z DEBUG stdout=active 2022-12-17T23:51:17Z DEBUG stderr= 2022-12-17T23:51:17Z DEBUG Restart of kadmin.service complete 2022-12-17T23:51:17Z DEBUG step duration: kadmin __start 0.19 sec 2022-12-17T23:51:17Z DEBUG [2/2]: configuring kadmin to start on boot 2022-12-17T23:51:17Z DEBUG Starting external process 2022-12-17T23:51:17Z DEBUG args=['/bin/systemctl', 'is-enabled', 'kadmin.service'] 2022-12-17T23:51:17Z DEBUG Process finished, return code=1 2022-12-17T23:51:17Z DEBUG stdout=disabled 2022-12-17T23:51:17Z DEBUG stderr= 2022-12-17T23:51:17Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:17Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:17Z DEBUG Starting external process 2022-12-17T23:51:17Z DEBUG args=['/bin/systemctl', 'unmask', 'kadmin.service'] 2022-12-17T23:51:18Z DEBUG Process finished, return code=0 2022-12-17T23:51:18Z DEBUG stdout= 2022-12-17T23:51:18Z DEBUG stderr= 2022-12-17T23:51:18Z DEBUG Starting external process 2022-12-17T23:51:18Z DEBUG args=['/bin/systemctl', 'disable', 'kadmin.service'] 2022-12-17T23:51:18Z DEBUG Process finished, return code=0 2022-12-17T23:51:18Z DEBUG stdout= 2022-12-17T23:51:18Z DEBUG stderr= 2022-12-17T23:51:18Z DEBUG step duration: kadmin __enable 0.80 sec 2022-12-17T23:51:18Z DEBUG Done configuring kadmin. 2022-12-17T23:51:18Z DEBUG service duration: kadmin 0.99 sec 2022-12-17T23:51:20Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:51:20Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:51:20Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:51:20Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:51:20Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:51:20Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:51:20Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:51:20Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:51:20Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:51:21Z DEBUG Created connection context.ldap2_139924023568592 2022-12-17T23:51:21Z DEBUG Custodia client for '' with promotion no. 2022-12-17T23:51:21Z DEBUG Custodia uses LDAPI. 2022-12-17T23:51:21Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:21Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:51:21Z DEBUG Configuring ipa-custodia 2022-12-17T23:51:21Z DEBUG [1/5]: Making sure custodia container exists 2022-12-17T23:51:21Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:51:21Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:51:21Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:51:21Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:51:21Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:51:21Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:51:21Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:51:21Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:51:21Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:51:22Z DEBUG Created connection context.ldap2_139924013616592 2022-12-17T23:51:22Z DEBUG raw: idrange_show('REDACTED_DOMAIN.COM_id_range', version='2.251') 2022-12-17T23:51:22Z DEBUG idrange_show('REDACTED_DOMAIN.COM_id_range', rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:51:22Z DEBUG flushing ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:51:22Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:51:22Z DEBUG Parsing update file '/usr/share/ipa/updates/73-custodia.update' 2022-12-17T23:51:22Z DEBUG Updating existing entry: cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:51:22Z DEBUG --------------------------------------------- 2022-12-17T23:51:22Z DEBUG Initial value 2022-12-17T23:51:22Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:51:22Z DEBUG objectClass: 2022-12-17T23:51:22Z DEBUG nsContainer 2022-12-17T23:51:22Z DEBUG top 2022-12-17T23:51:22Z DEBUG cn: 2022-12-17T23:51:22Z DEBUG custodia 2022-12-17T23:51:22Z DEBUG --------------------------------------------- 2022-12-17T23:51:22Z DEBUG Final value after applying updates 2022-12-17T23:51:22Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:51:22Z DEBUG objectClass: 2022-12-17T23:51:22Z DEBUG nsContainer 2022-12-17T23:51:22Z DEBUG top 2022-12-17T23:51:22Z DEBUG cn: 2022-12-17T23:51:22Z DEBUG custodia 2022-12-17T23:51:22Z DEBUG [] 2022-12-17T23:51:22Z DEBUG Updated 0 2022-12-17T23:51:22Z DEBUG Done 2022-12-17T23:51:22Z DEBUG Updating existing entry: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:51:22Z DEBUG --------------------------------------------- 2022-12-17T23:51:22Z DEBUG Initial value 2022-12-17T23:51:22Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:51:22Z DEBUG objectClass: 2022-12-17T23:51:22Z DEBUG nsContainer 2022-12-17T23:51:22Z DEBUG top 2022-12-17T23:51:22Z DEBUG cn: 2022-12-17T23:51:22Z DEBUG dogtag 2022-12-17T23:51:22Z DEBUG --------------------------------------------- 2022-12-17T23:51:22Z DEBUG Final value after applying updates 2022-12-17T23:51:22Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:51:22Z DEBUG objectClass: 2022-12-17T23:51:22Z DEBUG nsContainer 2022-12-17T23:51:22Z DEBUG top 2022-12-17T23:51:22Z DEBUG cn: 2022-12-17T23:51:22Z DEBUG dogtag 2022-12-17T23:51:22Z DEBUG [] 2022-12-17T23:51:22Z DEBUG Updated 0 2022-12-17T23:51:22Z DEBUG Done 2022-12-17T23:51:22Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-custodia.update 0.005 sec 2022-12-17T23:51:22Z DEBUG Destroyed connection context.ldap2_139924013616592 2022-12-17T23:51:22Z DEBUG step duration: ipa-custodia __create_container 1.10 sec 2022-12-17T23:51:22Z DEBUG [2/5]: Generating ipa-custodia config file 2022-12-17T23:51:22Z DEBUG step duration: ipa-custodia __config_file 0.00 sec 2022-12-17T23:51:22Z DEBUG [3/5]: Generating ipa-custodia keys 2022-12-17T23:51:23Z DEBUG step duration: ipa-custodia __gen_keys 0.63 sec 2022-12-17T23:51:23Z DEBUG [4/5]: starting ipa-custodia 2022-12-17T23:51:23Z DEBUG Starting external process 2022-12-17T23:51:23Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-custodia.service'] 2022-12-17T23:51:23Z DEBUG Process finished, return code=3 2022-12-17T23:51:23Z DEBUG stdout=inactive 2022-12-17T23:51:23Z DEBUG stderr= 2022-12-17T23:51:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:23Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:23Z DEBUG Starting external process 2022-12-17T23:51:23Z DEBUG args=['/bin/systemctl', 'restart', 'ipa-custodia.service'] 2022-12-17T23:51:23Z DEBUG Process finished, return code=0 2022-12-17T23:51:23Z DEBUG stdout= 2022-12-17T23:51:23Z DEBUG stderr= 2022-12-17T23:51:23Z DEBUG Starting external process 2022-12-17T23:51:23Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-custodia.service'] 2022-12-17T23:51:23Z DEBUG Process finished, return code=0 2022-12-17T23:51:23Z DEBUG stdout=active 2022-12-17T23:51:23Z DEBUG stderr= 2022-12-17T23:51:23Z DEBUG Restart of ipa-custodia.service complete 2022-12-17T23:51:23Z DEBUG step duration: ipa-custodia __start 0.67 sec 2022-12-17T23:51:23Z DEBUG [5/5]: configuring ipa-custodia to start on boot 2022-12-17T23:51:23Z DEBUG Starting external process 2022-12-17T23:51:23Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ipa-custodia.service'] 2022-12-17T23:51:23Z DEBUG Process finished, return code=1 2022-12-17T23:51:23Z DEBUG stdout=disabled 2022-12-17T23:51:23Z DEBUG stderr= 2022-12-17T23:51:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:23Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:23Z DEBUG Starting external process 2022-12-17T23:51:23Z DEBUG args=['/bin/systemctl', 'unmask', 'ipa-custodia.service'] 2022-12-17T23:51:24Z DEBUG Process finished, return code=0 2022-12-17T23:51:24Z DEBUG stdout= 2022-12-17T23:51:24Z DEBUG stderr= 2022-12-17T23:51:24Z DEBUG Starting external process 2022-12-17T23:51:24Z DEBUG args=['/bin/systemctl', 'disable', 'ipa-custodia.service'] 2022-12-17T23:51:24Z DEBUG Process finished, return code=0 2022-12-17T23:51:24Z DEBUG stdout= 2022-12-17T23:51:24Z DEBUG stderr= 2022-12-17T23:51:24Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:51:24Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:51:24Z DEBUG step duration: ipa-custodia __enable 0.92 sec 2022-12-17T23:51:24Z DEBUG Done configuring ipa-custodia. 2022-12-17T23:51:24Z DEBUG service duration: ipa-custodia 3.32 sec 2022-12-17T23:51:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:51:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:51:24Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:51:26Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:51:26Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:51:26Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:51:26Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:51:26Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:51:26Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:51:26Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:51:26Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:51:26Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:51:26Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:51:27Z DEBUG Created connection context.ldap2_140111978781200 2022-12-17T23:51:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:27Z DEBUG Custodia client for '' with promotion no. 2022-12-17T23:51:27Z DEBUG Custodia uses LDAPI. 2022-12-17T23:51:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:27Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:51:27Z DEBUG Configuring ipa-custodia 2022-12-17T23:51:27Z DEBUG [1/5]: Making sure custodia container exists 2022-12-17T23:51:27Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:51:27Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:51:27Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:51:27Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:51:27Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:51:27Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:51:27Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:51:27Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:51:27Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:51:28Z DEBUG Created connection context.ldap2_140111968850640 2022-12-17T23:51:28Z DEBUG raw: idrange_show('REDACTED_DOMAIN.COM_id_range', version='2.251') 2022-12-17T23:51:28Z DEBUG idrange_show('REDACTED_DOMAIN.COM_id_range', rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:51:28Z DEBUG flushing ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:51:28Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:51:28Z DEBUG Parsing update file '/usr/share/ipa/updates/73-custodia.update' 2022-12-17T23:51:28Z DEBUG Updating existing entry: cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:51:28Z DEBUG --------------------------------------------- 2022-12-17T23:51:28Z DEBUG Initial value 2022-12-17T23:51:28Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:51:28Z DEBUG objectClass: 2022-12-17T23:51:28Z DEBUG nsContainer 2022-12-17T23:51:28Z DEBUG top 2022-12-17T23:51:28Z DEBUG cn: 2022-12-17T23:51:28Z DEBUG custodia 2022-12-17T23:51:28Z DEBUG --------------------------------------------- 2022-12-17T23:51:28Z DEBUG Final value after applying updates 2022-12-17T23:51:28Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:51:28Z DEBUG objectClass: 2022-12-17T23:51:28Z DEBUG nsContainer 2022-12-17T23:51:28Z DEBUG top 2022-12-17T23:51:28Z DEBUG cn: 2022-12-17T23:51:28Z DEBUG custodia 2022-12-17T23:51:28Z DEBUG [] 2022-12-17T23:51:28Z DEBUG Updated 0 2022-12-17T23:51:28Z DEBUG Done 2022-12-17T23:51:28Z DEBUG Updating existing entry: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:51:28Z DEBUG --------------------------------------------- 2022-12-17T23:51:28Z DEBUG Initial value 2022-12-17T23:51:28Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:51:28Z DEBUG objectClass: 2022-12-17T23:51:28Z DEBUG nsContainer 2022-12-17T23:51:28Z DEBUG top 2022-12-17T23:51:28Z DEBUG cn: 2022-12-17T23:51:28Z DEBUG dogtag 2022-12-17T23:51:28Z DEBUG --------------------------------------------- 2022-12-17T23:51:28Z DEBUG Final value after applying updates 2022-12-17T23:51:28Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:51:28Z DEBUG objectClass: 2022-12-17T23:51:28Z DEBUG nsContainer 2022-12-17T23:51:28Z DEBUG top 2022-12-17T23:51:28Z DEBUG cn: 2022-12-17T23:51:28Z DEBUG dogtag 2022-12-17T23:51:28Z DEBUG [] 2022-12-17T23:51:28Z DEBUG Updated 0 2022-12-17T23:51:28Z DEBUG Done 2022-12-17T23:51:28Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-custodia.update 0.006 sec 2022-12-17T23:51:28Z DEBUG Destroyed connection context.ldap2_140111968850640 2022-12-17T23:51:28Z DEBUG step duration: ipa-custodia __create_container 1.17 sec 2022-12-17T23:51:28Z DEBUG [2/5]: Generating ipa-custodia config file 2022-12-17T23:51:28Z DEBUG step duration: ipa-custodia __config_file 0.00 sec 2022-12-17T23:51:28Z DEBUG [3/5]: Generating ipa-custodia keys 2022-12-17T23:51:29Z DEBUG step duration: ipa-custodia __gen_keys 0.78 sec 2022-12-17T23:51:29Z DEBUG [4/5]: starting ipa-custodia 2022-12-17T23:51:29Z DEBUG Starting external process 2022-12-17T23:51:29Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-custodia.service'] 2022-12-17T23:51:29Z DEBUG Process finished, return code=0 2022-12-17T23:51:29Z DEBUG stdout=active 2022-12-17T23:51:29Z DEBUG stderr= 2022-12-17T23:51:29Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:29Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:29Z DEBUG Starting external process 2022-12-17T23:51:29Z DEBUG args=['/bin/systemctl', 'restart', 'ipa-custodia.service'] 2022-12-17T23:51:30Z DEBUG Process finished, return code=0 2022-12-17T23:51:30Z DEBUG stdout= 2022-12-17T23:51:30Z DEBUG stderr= 2022-12-17T23:51:30Z DEBUG Starting external process 2022-12-17T23:51:30Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-custodia.service'] 2022-12-17T23:51:30Z DEBUG Process finished, return code=0 2022-12-17T23:51:30Z DEBUG stdout=active 2022-12-17T23:51:30Z DEBUG stderr= 2022-12-17T23:51:30Z DEBUG Restart of ipa-custodia.service complete 2022-12-17T23:51:30Z DEBUG step duration: ipa-custodia __start 0.61 sec 2022-12-17T23:51:30Z DEBUG [5/5]: configuring ipa-custodia to start on boot 2022-12-17T23:51:30Z DEBUG Starting external process 2022-12-17T23:51:30Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ipa-custodia.service'] 2022-12-17T23:51:30Z DEBUG Process finished, return code=1 2022-12-17T23:51:30Z DEBUG stdout=disabled 2022-12-17T23:51:30Z DEBUG stderr= 2022-12-17T23:51:30Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:30Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:30Z DEBUG Starting external process 2022-12-17T23:51:30Z DEBUG args=['/bin/systemctl', 'unmask', 'ipa-custodia.service'] 2022-12-17T23:51:30Z DEBUG Process finished, return code=0 2022-12-17T23:51:30Z DEBUG stdout= 2022-12-17T23:51:30Z DEBUG stderr= 2022-12-17T23:51:30Z DEBUG Starting external process 2022-12-17T23:51:30Z DEBUG args=['/bin/systemctl', 'disable', 'ipa-custodia.service'] 2022-12-17T23:51:31Z DEBUG Process finished, return code=0 2022-12-17T23:51:31Z DEBUG stdout= 2022-12-17T23:51:31Z DEBUG stderr= 2022-12-17T23:51:31Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:51:31Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:51:31Z DEBUG service KEYS: config string configuredService already set 2022-12-17T23:51:31Z DEBUG service KEYS has already enabled config values ['configuredService'] 2022-12-17T23:51:31Z DEBUG step duration: ipa-custodia __enable 0.93 sec 2022-12-17T23:51:31Z DEBUG Done configuring ipa-custodia. 2022-12-17T23:51:31Z DEBUG service duration: ipa-custodia 3.50 sec 2022-12-17T23:51:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:51:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:51:31Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:51:31Z DEBUG update_entry modlist [(2, 'ipacertificatesubjectbase', [b'O=REDACTED_DOMAIN.COM'])] 2022-12-17T23:51:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:51:31Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:51:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:31Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:51:31Z DEBUG Configuring certificate server (pki-tomcatd). Estimated time: 3 minutes 2022-12-17T23:51:31Z DEBUG [1/30]: configuring certificate server instance 2022-12-17T23:51:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:31Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:31Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:31Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:51:31Z DEBUG Contents of pkispawn configuration file (/tmp/tmpwx3vzomu): [CA] pki_admin_cert_file = /root/.dogtag/pki-tomcat/ca_admin.cert pki_admin_cert_request_type = pkcs10 pki_admin_dualkey = False pki_admin_email = root@localhost pki_admin_name = admin pki_admin_nickname = ipa-ca-agent pki_admin_password = XXXXXXXX pki_admin_subject_dn = cn=ipa-ca-agent,O=REDACTED_DOMAIN.COM pki_admin_uid = admin pki_ajp_host_ipv4 = 127.0.0.1 pki_ajp_host_ipv6 = ::1 pki_ajp_secret = 2QdfW5RDV1YdeJ25DZc2x0bADsldtuVnolNtDAuRY2iP pki_audit_group = pkiaudit pki_audit_signing_key_algorithm = SHA256withRSA pki_audit_signing_key_size = 2048 pki_audit_signing_key_type = rsa pki_audit_signing_nickname = auditSigningCert cert-pki-ca pki_audit_signing_signing_algorithm = SHA256withRSA pki_audit_signing_subject_dn = cn=CA Audit,O=REDACTED_DOMAIN.COM pki_audit_signing_token = internal pki_backup_keys = True pki_backup_password = XXXXXXXX pki_ca_hostname = master.redacted_domain.com pki_ca_port = 443 pki_ca_signing_cert_path = /etc/pki/pki-tomcat/external_ca.cert pki_ca_signing_csr_path = /root/ipa.csr pki_ca_signing_key_algorithm = SHA256withRSA pki_ca_signing_key_size = 3072 pki_ca_signing_key_type = rsa pki_ca_signing_nickname = caSigningCert cert-pki-ca pki_ca_signing_record_create = True pki_ca_signing_serial_number = 1 pki_ca_signing_signing_algorithm = SHA512withRSA pki_ca_signing_subject_dn = CN=Certificate Authority,O=REDACTED_DOMAIN.COM pki_ca_signing_token = internal pki_ca_starting_crl_number = 0 pki_cert_chain_nickname = caSigningCert External CA pki_cert_chain_path = /etc/pki/pki-tomcat/external_ca_chain.cert pki_cert_id_generator = legacy pki_client_admin_cert_p12 = /root/ca-agent.p12 pki_client_database_password = pki_client_database_purge = True pki_client_dir = /root/.dogtag/pki-tomcat pki_client_pkcs12_password = XXXXXXXX pki_configuration_path = /etc/pki pki_default_ocsp_uri = http://ipa-ca.redacted_domain.com/ca/ocsp pki_dns_domainname = redacted_domain.com pki_ds_base_dn = o=ipaca pki_ds_bind_dn = cn=Directory Manager pki_ds_database = ipaca pki_ds_hostname = master.redacted_domain.com pki_ds_ldap_port = 389 pki_ds_ldaps_port = 636 pki_ds_password = XXXXXXXX pki_ds_remove_data = True pki_ds_secure_connection = False pki_ds_secure_connection_ca_nickname = Directory Server CA certificate pki_ds_secure_connection_ca_pem_file = /etc/ipa/ca.crt pki_enable_proxy = True pki_existing = False pki_external = False pki_external_pkcs12_password = pki_external_pkcs12_path = pki_external_step_two = False pki_group = pkiuser pki_hostname = master.redacted_domain.com pki_hsm_enable = False pki_hsm_libfile = pki_hsm_modulename = pki_import_admin_cert = False pki_instance_configuration_path = /etc/pki/pki-tomcat pki_instance_name = pki-tomcat pki_issuing_ca = https://master.redacted_domain.com:443 pki_issuing_ca_hostname = master.redacted_domain.com pki_issuing_ca_https_port = 443 pki_issuing_ca_uri = https://master.redacted_domain.com:443 pki_master_crl_enable = True pki_ocsp_signing_key_algorithm = SHA256withRSA pki_ocsp_signing_key_size = 2048 pki_ocsp_signing_key_type = rsa pki_ocsp_signing_nickname = ocspSigningCert cert-pki-ca pki_ocsp_signing_signing_algorithm = SHA256withRSA pki_ocsp_signing_subject_dn = cn=OCSP Subsystem,O=REDACTED_DOMAIN.COM pki_ocsp_signing_token = internal pki_pkcs12_password = pki_pkcs12_path = pki_profiles_in_ldap = True pki_random_serial_numbers_enable = False pki_replica_number_range_end = 100 pki_replica_number_range_start = 1 pki_replication_password = pki_request_id_generator = legacy pki_request_number_range_end = 10000000 pki_request_number_range_start = 1 pki_san_for_server_cert = pki_san_inject = False pki_security_domain_hostname = master.redacted_domain.com pki_security_domain_https_port = 443 pki_security_domain_name = IPA pki_security_domain_password = XXXXXXXX pki_security_domain_user = admin pki_self_signed_token = internal pki_serial_number_range_end = 10000000 pki_serial_number_range_start = 1 pki_server_database_password = XXXXXXXX pki_share_db = False pki_skip_configuration = False pki_skip_ds_verify = False pki_skip_installation = False pki_skip_sd_verify = False pki_sslserver_key_algorithm = SHA256withRSA pki_sslserver_key_size = 2048 pki_sslserver_key_type = rsa pki_sslserver_nickname = Server-Cert cert-pki-ca pki_sslserver_subject_dn = cn=master.redacted_domain.com,O=REDACTED_DOMAIN.COM pki_sslserver_token = internal pki_status_request_timeout = 15 pki_subordinate = False pki_subordinate_create_new_security_domain = False pki_subsystem = CA pki_subsystem_key_algorithm = SHA256withRSA pki_subsystem_key_size = 2048 pki_subsystem_key_type = rsa pki_subsystem_nickname = subsystemCert cert-pki-ca pki_subsystem_subject_dn = cn=CA Subsystem,O=REDACTED_DOMAIN.COM pki_subsystem_token = internal pki_subsystem_type = ca pki_theme_enable = True pki_theme_server_dir = /usr/share/pki/common-ui pki_token_name = internal pki_user = pkiuser 2022-12-17T23:51:31Z DEBUG Starting external process 2022-12-17T23:51:31Z DEBUG args=['/usr/sbin/pkispawn', '-s', 'CA', '-f', '/tmp/tmpwx3vzomu', '--debug', '--log-file', '/var/log/pki/pki-ca-spawn.20221218005131.log'] 2022-12-17T23:53:55Z DEBUG Process finished, return code=0 2022-12-17T23:53:55Z DEBUG stdout=--------------- Export complete --------------- Loading deployment configuration from /tmp/tmpwx3vzomu. Installation log: /var/log/pki/pki-ca-spawn.20221218005131.log Installing CA into /var/lib/pki/pki-tomcat. ========================================================================== INSTALLATION SUMMARY ========================================================================== Administrator's username: admin Administrator's PKCS #12 file: /root/ca-agent.p12 To check the status of the subsystem: systemctl status pki-tomcatd@pki-tomcat.service To restart the subsystem: systemctl restart pki-tomcatd@pki-tomcat.service The URL for the subsystem is: https://master.redacted_domain.com:8443/ca PKI instances will be enabled upon system boot ========================================================================== 2022-12-17T23:53:55Z DEBUG stderr=INFO: Connecting to LDAP server at ldap://master.redacted_domain.com:389 INFO: Connecting to LDAP server at ldap://master.redacted_domain.com:389 INFO: BEGIN spawning CA subsystem in pki-tomcat instance INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Setting up pkiuser group INFO: Reusing existing pkiuser group with GID 17 INFO: Setting up pkiuser user INFO: Reusing existing pkiuser user with UID 17 DEBUG: Retrieving UID for 'pkiuser' DEBUG: UID of 'pkiuser' is 17 DEBUG: Retrieving GID for 'pkiuser' DEBUG: GID of 'pkiuser' is 17 INFO: Initialization INFO: Setting up infrastructure INFO: Creating /etc/sysconfig/pki/tomcat/pki-tomcat DEBUG: Command: mkdir -p /etc/sysconfig/pki/tomcat/pki-tomcat DEBUG: Command: chmod 770 /etc/sysconfig/pki/tomcat/pki-tomcat DEBUG: Command: chown 17:17 /etc/sysconfig/pki/tomcat/pki-tomcat INFO: Creating /etc/sysconfig/pki/tomcat/pki-tomcat/ca DEBUG: Command: mkdir -p /etc/sysconfig/pki/tomcat/pki-tomcat/ca DEBUG: Command: chmod 770 /etc/sysconfig/pki/tomcat/pki-tomcat/ca DEBUG: Command: chown 17:17 /etc/sysconfig/pki/tomcat/pki-tomcat/ca INFO: Creating /etc/sysconfig/pki/tomcat/pki-tomcat/ca/default.cfg DEBUG: Command: cp -p /usr/share/pki/server/etc/default.cfg /etc/sysconfig/pki/tomcat/pki-tomcat/ca/default.cfg DEBUG: Command: chmod 660 /etc/sysconfig/pki/tomcat/pki-tomcat/ca/default.cfg DEBUG: Command: chown 17:17 /etc/sysconfig/pki/tomcat/pki-tomcat/ca/default.cfg DEBUG: Command: touch /etc/sysconfig/pki/tomcat/pki-tomcat/ca/deployment.cfg DEBUG: Command: chmod 660 /etc/sysconfig/pki/tomcat/pki-tomcat/ca/deployment.cfg DEBUG: Command: chown 17:17 /etc/sysconfig/pki/tomcat/pki-tomcat/ca/deployment.cfg INFO: Creating /var/lib/pki/pki-tomcat DEBUG: Command: mkdir -p /var/lib/pki/pki-tomcat DEBUG: Command: chmod 770 /var/lib/pki/pki-tomcat DEBUG: Command: chown 17:17 /var/lib/pki/pki-tomcat INFO: Creating /var/lib/pki/pki-tomcat/ca DEBUG: Command: mkdir -p /var/lib/pki/pki-tomcat/ca DEBUG: Command: chmod 770 /var/lib/pki/pki-tomcat/ca DEBUG: Command: chown 17:17 /var/lib/pki/pki-tomcat/ca INFO: Preparing pki-tomcat instance INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Creating /etc/pki/pki-tomcat INFO: Creating /etc/pki/pki-tomcat DEBUG: Command: mkdir /etc/pki/pki-tomcat INFO: Creating /etc/pki/pki-tomcat/password.conf INFO: Using specified server NSS database password INFO: Using specified internal database password INFO: Generating random replication manager password INFO: Creating /var/log/pki/pki-tomcat DEBUG: Command: mkdir -p /var/log/pki/pki-tomcat DEBUG: Command: chmod 770 /var/log/pki/pki-tomcat DEBUG: Command: chown 17:17 /var/log/pki/pki-tomcat INFO: Creating /etc/pki/pki-tomcat/tomcat.conf DEBUG: Command: cp /usr/share/pki/server/conf/tomcat.conf /etc/pki/pki-tomcat/tomcat.conf INFO: Creating /etc/pki/pki-tomcat/server.xml DEBUG: Command: cp /usr/share/pki/server/conf/server.xml /etc/pki/pki-tomcat/server.xml INFO: Creating /etc/pki/pki-tomcat/catalina.properties DEBUG: Command: ln -s /usr/share/pki/server/conf/catalina.properties /etc/pki/pki-tomcat/catalina.properties INFO: Creating /etc/pki/pki-tomcat/context.xml DEBUG: Command: ln -s /etc/tomcat/context.xml /etc/pki/pki-tomcat/context.xml INFO: Creating /etc/pki/pki-tomcat/logging.properties DEBUG: Command: ln -s /usr/share/pki/server/conf/logging.properties /etc/pki/pki-tomcat/logging.properties INFO: Creating /etc/sysconfig/pki-tomcat DEBUG: Command: cp /usr/share/pki/server/conf/tomcat.conf /etc/sysconfig/pki-tomcat INFO: Creating /etc/pki/pki-tomcat/tomcat.conf DEBUG: Command: cp /usr/share/pki/server/conf/tomcat.conf /etc/pki/pki-tomcat/tomcat.conf INFO: Creating /etc/pki/pki-tomcat/web.xml DEBUG: Command: ln -s /etc/tomcat/web.xml /etc/pki/pki-tomcat/web.xml INFO: Creating /etc/pki/pki-tomcat/Catalina DEBUG: Command: mkdir /etc/pki/pki-tomcat/Catalina INFO: Creating /etc/pki/pki-tomcat/Catalina/localhost DEBUG: Command: mkdir /etc/pki/pki-tomcat/Catalina/localhost INFO: Deploying ROOT web application INFO: Creating /etc/pki/pki-tomcat/Catalina/localhost/ROOT.xml INFO: Deploying /pki web application INFO: Creating /etc/pki/pki-tomcat/Catalina/localhost/pki.xml INFO: Creating /var/lib/pki/pki-tomcat/lib DEBUG: Command: ln -s /usr/share/pki/server/lib /var/lib/pki/pki-tomcat/lib INFO: Creating /var/lib/pki/pki-tomcat/common DEBUG: Command: mkdir /var/lib/pki/pki-tomcat/common INFO: Creating /var/lib/pki/pki-tomcat/common/lib DEBUG: Command: ln -s /usr/share/pki/server/common/lib /var/lib/pki/pki-tomcat/common/lib INFO: Creating /var/lib/pki/pki-tomcat/temp DEBUG: Command: mkdir -p /var/lib/pki/pki-tomcat/temp DEBUG: Command: chmod 770 /var/lib/pki/pki-tomcat/temp DEBUG: Command: chown 17:17 /var/lib/pki/pki-tomcat/temp INFO: Creating /var/lib/pki/pki-tomcat/work DEBUG: Command: mkdir -p /var/lib/pki/pki-tomcat/work DEBUG: Command: chmod 770 /var/lib/pki/pki-tomcat/work DEBUG: Command: chown 17:17 /var/lib/pki/pki-tomcat/work INFO: Creating /var/lib/pki/pki-tomcat/work/Catalina DEBUG: Command: mkdir -p /var/lib/pki/pki-tomcat/work/Catalina DEBUG: Command: chmod 770 /var/lib/pki/pki-tomcat/work/Catalina DEBUG: Command: chown 17:17 /var/lib/pki/pki-tomcat/work/Catalina INFO: Creating /var/lib/pki/pki-tomcat/work/Catalina/localhost DEBUG: Command: mkdir -p /var/lib/pki/pki-tomcat/work/Catalina/localhost DEBUG: Command: chmod 770 /var/lib/pki/pki-tomcat/work/Catalina/localhost DEBUG: Command: chown 17:17 /var/lib/pki/pki-tomcat/work/Catalina/localhost INFO: Creating /var/lib/pki/pki-tomcat/work/Catalina/localhost/_ DEBUG: Command: mkdir -p /var/lib/pki/pki-tomcat/work/Catalina/localhost/_ DEBUG: Command: chmod 770 /var/lib/pki/pki-tomcat/work/Catalina/localhost/_ DEBUG: Command: chown 17:17 /var/lib/pki/pki-tomcat/work/Catalina/localhost/_ INFO: Creating /var/lib/pki/pki-tomcat/work/Catalina/localhost/ca DEBUG: Command: mkdir -p /var/lib/pki/pki-tomcat/work/Catalina/localhost/ca DEBUG: Command: chmod 770 /var/lib/pki/pki-tomcat/work/Catalina/localhost/ca DEBUG: Command: chown 17:17 /var/lib/pki/pki-tomcat/work/Catalina/localhost/ca INFO: Creating /var/lib/pki/pki-tomcat/bin DEBUG: Command: ln -s /usr/share/tomcat/bin /var/lib/pki/pki-tomcat/bin DEBUG: Command: chown -h 17:17 /var/lib/pki/pki-tomcat/bin DEBUG: Command: systemctl daemon-reload INFO: Creating /var/lib/pki/pki-tomcat/conf DEBUG: Command: ln -s /etc/pki/pki-tomcat /var/lib/pki/pki-tomcat/conf DEBUG: Command: chown -h 17:17 /var/lib/pki/pki-tomcat/conf INFO: Creating /var/lib/pki/pki-tomcat/logs DEBUG: Command: ln -s /var/log/pki/pki-tomcat /var/lib/pki/pki-tomcat/logs DEBUG: Command: chown -h 17:17 /var/lib/pki/pki-tomcat/logs INFO: Creating /etc/systemd/system/pki-tomcatd.target.wants/pki-tomcatd@pki-tomcat.service DEBUG: Command: ln -s /lib/systemd/system/pki-tomcatd@.service /etc/systemd/system/pki-tomcatd.target.wants/pki-tomcatd@pki-tomcat.service DEBUG: Command: chown -h 17:17 /etc/systemd/system/pki-tomcatd.target.wants/pki-tomcatd@pki-tomcat.service INFO: Creating /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: Command: cp /usr/share/pki/setup/pkidaemon_registry /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat INFO: Creating CA subsystem INFO: Creating /var/log/pki/pki-tomcat/ca DEBUG: Command: mkdir /var/log/pki/pki-tomcat/ca INFO: Creating /var/log/pki/pki-tomcat/ca/archive DEBUG: Command: mkdir /var/log/pki/pki-tomcat/ca/archive INFO: Creating /var/log/pki/pki-tomcat/ca/signedAudit DEBUG: Command: mkdir /var/log/pki/pki-tomcat/ca/signedAudit INFO: Creating /etc/pki/pki-tomcat/ca DEBUG: Command: mkdir /etc/pki/pki-tomcat/ca INFO: Creating /etc/pki/pki-tomcat/ca/CS.cfg DEBUG: Command: cp /usr/share/pki/ca/conf/CS.cfg /etc/pki/pki-tomcat/ca/CS.cfg INFO: Creating /etc/pki/pki-tomcat/ca/registry.cfg DEBUG: Command: cp /usr/share/pki/ca/conf/registry.cfg /etc/pki/pki-tomcat/ca/registry.cfg INFO: Creating /etc/pki/pki-tomcat/ca/emails DEBUG: Command: mkdir /etc/pki/pki-tomcat/ca/emails DEBUG: Command: cp /usr/share/pki/ca/emails/ExpiredUnpublishJob /etc/pki/pki-tomcat/ca/emails/ExpiredUnpublishJob DEBUG: Command: cp /usr/share/pki/ca/emails/ExpiredUnpublishJobItem /etc/pki/pki-tomcat/ca/emails/ExpiredUnpublishJobItem DEBUG: Command: cp /usr/share/pki/ca/emails/certIssued_CA /etc/pki/pki-tomcat/ca/emails/certIssued_CA DEBUG: Command: cp /usr/share/pki/ca/emails/certIssued_CA.html /etc/pki/pki-tomcat/ca/emails/certIssued_CA.html DEBUG: Command: cp /usr/share/pki/ca/emails/certIssued_RA /etc/pki/pki-tomcat/ca/emails/certIssued_RA DEBUG: Command: cp /usr/share/pki/ca/emails/certIssued_RA.html /etc/pki/pki-tomcat/ca/emails/certIssued_RA.html DEBUG: Command: cp /usr/share/pki/ca/emails/certRequestRejected.html /etc/pki/pki-tomcat/ca/emails/certRequestRejected.html DEBUG: Command: cp /usr/share/pki/ca/emails/certRevoked_CA /etc/pki/pki-tomcat/ca/emails/certRevoked_CA DEBUG: Command: cp /usr/share/pki/ca/emails/certRevoked_CA.html /etc/pki/pki-tomcat/ca/emails/certRevoked_CA.html DEBUG: Command: cp /usr/share/pki/ca/emails/certRevoked_RA /etc/pki/pki-tomcat/ca/emails/certRevoked_RA DEBUG: Command: cp /usr/share/pki/ca/emails/certRevoked_RA.html /etc/pki/pki-tomcat/ca/emails/certRevoked_RA.html DEBUG: Command: cp /usr/share/pki/ca/emails/euJob1.html /etc/pki/pki-tomcat/ca/emails/euJob1.html DEBUG: Command: cp /usr/share/pki/ca/emails/euJob1Item.html /etc/pki/pki-tomcat/ca/emails/euJob1Item.html DEBUG: Command: cp /usr/share/pki/ca/emails/publishCerts.html /etc/pki/pki-tomcat/ca/emails/publishCerts.html DEBUG: Command: cp /usr/share/pki/ca/emails/publishCertsItem.html /etc/pki/pki-tomcat/ca/emails/publishCertsItem.html DEBUG: Command: cp /usr/share/pki/ca/emails/reqInQueue_CA /etc/pki/pki-tomcat/ca/emails/reqInQueue_CA DEBUG: Command: cp /usr/share/pki/ca/emails/reqInQueue_CA.html /etc/pki/pki-tomcat/ca/emails/reqInQueue_CA.html DEBUG: Command: cp /usr/share/pki/ca/emails/reqInQueue_RA /etc/pki/pki-tomcat/ca/emails/reqInQueue_RA DEBUG: Command: cp /usr/share/pki/ca/emails/reqInQueue_RA.html /etc/pki/pki-tomcat/ca/emails/reqInQueue_RA.html DEBUG: Command: cp /usr/share/pki/ca/emails/riq1Item.html /etc/pki/pki-tomcat/ca/emails/riq1Item.html DEBUG: Command: cp /usr/share/pki/ca/emails/riq1Summary.html /etc/pki/pki-tomcat/ca/emails/riq1Summary.html DEBUG: Command: cp /usr/share/pki/ca/emails/rnJob1.txt /etc/pki/pki-tomcat/ca/emails/rnJob1.txt DEBUG: Command: cp /usr/share/pki/ca/emails/rnJob1Item.txt /etc/pki/pki-tomcat/ca/emails/rnJob1Item.txt DEBUG: Command: cp /usr/share/pki/ca/emails/rnJob1Summary.txt /etc/pki/pki-tomcat/ca/emails/rnJob1Summary.txt INFO: Creating /var/lib/pki/pki-tomcat/ca/emails DEBUG: Command: ln -s /etc/pki/pki-tomcat/ca/emails /var/lib/pki/pki-tomcat/ca/emails INFO: Creating /etc/pki/pki-tomcat/ca/profiles DEBUG: Command: mkdir /etc/pki/pki-tomcat/ca/profiles DEBUG: Command: mkdir /etc/pki/pki-tomcat/ca/profiles/ca DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/DomainController.cfg /etc/pki/pki-tomcat/ca/profiles/ca/DomainController.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/ECAdminCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/ECAdminCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/acmeServerCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/acmeServerCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caAdminCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caAdminCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caAgentFileSigning.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caAgentFileSigning.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caAgentServerCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caAgentServerCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caAuditSigningCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caAuditSigningCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCACert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caCACert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCECUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caCMCECUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCECserverCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caCMCECserverCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCECsubsystemCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caCMCECsubsystemCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caCMCUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCauditSigningCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caCMCauditSigningCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCcaCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caCMCcaCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCcaIssuanceProtectionCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caCMCcaIssuanceProtectionCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCkraStorageCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caCMCkraStorageCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCkraTransportCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caCMCkraTransportCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCocspCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caCMCocspCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCserverCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caCMCserverCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCMCsubsystemCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caCMCsubsystemCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caCrossSignedCACert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caCrossSignedCACert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caDirBasedDualCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caDirBasedDualCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caDirPinUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caDirPinUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caDirUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caDirUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caDirUserRenewal.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caDirUserRenewal.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caDualCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caDualCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caDualRAuserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caDualRAuserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECAdminCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECAdminCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECAgentServerCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECAgentServerCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECDirPinUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECDirPinUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECDirUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECDirUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECDualCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECDualCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECFullCMCSharedTokenCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECFullCMCSharedTokenCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECFullCMCUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECFullCMCUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECFullCMCUserSignedCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECFullCMCUserSignedCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECInternalAuthServerCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECInternalAuthServerCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECInternalAuthSubsystemCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECInternalAuthSubsystemCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECServerCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECServerCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECServerCertWithSCT.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECServerCertWithSCT.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECSimpleCMCUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECSimpleCMCUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECSubsystemCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECSubsystemCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caECUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caECUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caEncECUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caEncECUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caEncUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caEncUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caFullCMCSharedTokenCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caFullCMCSharedTokenCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caFullCMCUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caFullCMCUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caFullCMCUserSignedCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caFullCMCUserSignedCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caIPAserviceCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caIPAserviceCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caInstallCACert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caInstallCACert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caInternalAuthAuditSigningCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthAuditSigningCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caInternalAuthDRMstorageCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthDRMstorageCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caInternalAuthOCSPCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthOCSPCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caInternalAuthServerCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthServerCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caInternalAuthSubsystemCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthSubsystemCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caInternalAuthTransportCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caInternalAuthTransportCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caJarSigningCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caJarSigningCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caManualRenewal.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caManualRenewal.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caOCSPCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caOCSPCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caOtherCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caOtherCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caRACert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caRACert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caRARouterCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caRARouterCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caRAagentCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caRAagentCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caRAserverCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caRAserverCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caRouterCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caRouterCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caSSLClientSelfRenewal.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caSSLClientSelfRenewal.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caServerCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caServerCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caServerCertWithSCT.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caServerCertWithSCT.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caServerKeygen_DirUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caServerKeygen_DirUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caServerKeygen_UserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caServerKeygen_UserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caSignedLogCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caSignedLogCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caSigningECUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caSigningECUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caSigningUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caSigningUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caSimpleCMCUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caSimpleCMCUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caStorageCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caStorageCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caSubsystemCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caSubsystemCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTPSCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caTPSCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTempTokenDeviceKeyEnrollment.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caTempTokenDeviceKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTempTokenUserEncryptionKeyEnrollment.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caTempTokenUserEncryptionKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTempTokenUserSigningKeyEnrollment.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caTempTokenUserSigningKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenDeviceKeyEnrollment.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caTokenDeviceKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenMSLoginEnrollment.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caTokenMSLoginEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenUserAuthKeyRenewal.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caTokenUserAuthKeyRenewal.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenUserDelegateAuthKeyEnrollment.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caTokenUserDelegateAuthKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenUserDelegateSigningKeyEnrollment.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caTokenUserDelegateSigningKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenUserEncryptionKeyEnrollment.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caTokenUserEncryptionKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenUserEncryptionKeyRenewal.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caTokenUserEncryptionKeyRenewal.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenUserSigningKeyEnrollment.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caTokenUserSigningKeyEnrollment.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTokenUserSigningKeyRenewal.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caTokenUserSigningKeyRenewal.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caTransportCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caTransportCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caUUIDdeviceCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caUUIDdeviceCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caUserCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caUserCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/caUserSMIMEcapCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/caUserSMIMEcapCert.cfg DEBUG: Command: cp /usr/share/pki/ca/profiles/ca/AdminCert.cfg /etc/pki/pki-tomcat/ca/profiles/ca/AdminCert.cfg INFO: Creating /var/lib/pki/pki-tomcat/ca/profiles DEBUG: Command: ln -s /etc/pki/pki-tomcat/ca/profiles /var/lib/pki/pki-tomcat/ca/profiles INFO: Creating /etc/pki/pki-tomcat/ca/flatfile.txt DEBUG: Command: cp /usr/share/pki/ca/conf/flatfile.txt /etc/pki/pki-tomcat/ca/flatfile.txt INFO: Creating /etc/pki/pki-tomcat/ca/adminCert.profile DEBUG: Command: cp /usr/share/pki/ca/conf/rsaAdminCert.profile /etc/pki/pki-tomcat/ca/adminCert.profile INFO: Creating /etc/pki/pki-tomcat/ca/caAuditSigningCert.profile DEBUG: Command: cp /usr/share/pki/ca/conf/caAuditSigningCert.profile /etc/pki/pki-tomcat/ca/caAuditSigningCert.profile INFO: Creating /etc/pki/pki-tomcat/ca/caCert.profile DEBUG: Command: cp /usr/share/pki/ca/conf/caCert.profile /etc/pki/pki-tomcat/ca/caCert.profile INFO: Creating /etc/pki/pki-tomcat/ca/caOCSPCert.profile DEBUG: Command: cp /usr/share/pki/ca/conf/caOCSPCert.profile /etc/pki/pki-tomcat/ca/caOCSPCert.profile INFO: Creating /etc/pki/pki-tomcat/ca/serverCert.profile DEBUG: Command: cp /usr/share/pki/ca/conf/rsaServerCert.profile /etc/pki/pki-tomcat/ca/serverCert.profile INFO: Creating /etc/pki/pki-tomcat/ca/subsystemCert.profile DEBUG: Command: cp /usr/share/pki/ca/conf/rsaSubsystemCert.profile /etc/pki/pki-tomcat/ca/subsystemCert.profile INFO: Creating /etc/pki/pki-tomcat/ca/proxy.conf DEBUG: Command: cp /usr/share/pki/ca/conf/proxy.conf /etc/pki/pki-tomcat/ca/proxy.conf INFO: Creating /var/lib/pki/pki-tomcat/ca/conf DEBUG: Command: ln -s /etc/pki/pki-tomcat/ca /var/lib/pki/pki-tomcat/ca/conf INFO: Creating /var/lib/pki/pki-tomcat/ca/logs DEBUG: Command: ln -s /var/log/pki/pki-tomcat/ca /var/lib/pki/pki-tomcat/ca/logs INFO: Creating /var/lib/pki/pki-tomcat/ca/registry DEBUG: Command: ln -s /etc/sysconfig/pki/tomcat/pki-tomcat /var/lib/pki/pki-tomcat/ca/registry INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /etc/pki/pki-tomcat/tomcat.conf INFO: Loading password config: /etc/pki/pki-tomcat/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser DEBUG: PKISubsystem.get_subsystem_cert(signing) INFO: Getting signing cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(ocsp_signing) INFO: Getting ocsp_signing cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(sslserver) INFO: Getting sslserver cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(subsystem) INFO: Getting subsystem cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(audit_signing) INFO: Getting audit_signing cert info from CS.cfg INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /etc/pki/pki-tomcat/tomcat.conf INFO: Loading password config: /etc/pki/pki-tomcat/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser INFO: Creating password file: /etc/pki/pki-tomcat/pfile INFO: Updating /etc/pki/pki-tomcat/password.conf DEBUG: Command: chmod 660 /etc/pki/pki-tomcat/password.conf DEBUG: Command: chown 17:17 /etc/pki/pki-tomcat/password.conf INFO: Creating /etc/pki/pki-tomcat/alias DEBUG: Command: mkdir /etc/pki/pki-tomcat/alias INFO: Creating NSS database: /etc/pki/pki-tomcat/alias DEBUG: Command: certutil -N -d /etc/pki/pki-tomcat/alias -f /etc/pki/pki-tomcat/pfile INFO: Creating /var/lib/pki/pki-tomcat/alias DEBUG: Command: ln -s /etc/pki/pki-tomcat/alias /var/lib/pki/pki-tomcat/alias INFO: Creating /var/lib/pki/pki-tomcat/ca/alias DEBUG: Command: ln -s /var/lib/pki/pki-tomcat/alias /var/lib/pki/pki-tomcat/ca/alias INFO: Removing /etc/pki/pki-tomcat/pfile DEBUG: Command: rm -f /etc/pki/pki-tomcat/pfile DEBUG: PKISubsystem.get_subsystem_cert(signing) INFO: Getting signing cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(ocsp_signing) INFO: Getting ocsp_signing cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(sslserver) INFO: Getting sslserver cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(subsystem) INFO: Getting subsystem cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(audit_signing) INFO: Getting audit_signing cert info from CS.cfg INFO: Injecting SAN: False INFO: SSL server cert SAN: INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Creating /root/.dogtag/pki-tomcat/ca DEBUG: Command: mkdir -p /root/.dogtag/pki-tomcat/ca DEBUG: Command: chmod 755 /root/.dogtag/pki-tomcat/ca DEBUG: Command: chown 0:0 /root/.dogtag/pki-tomcat/ca INFO: Creating password file: /root/.dogtag/pki-tomcat/ca/password.conf INFO: Updating /root/.dogtag/pki-tomcat/ca/password.conf DEBUG: Command: chmod 660 /root/.dogtag/pki-tomcat/ca/password.conf DEBUG: Command: chown 0:0 /root/.dogtag/pki-tomcat/ca/password.conf INFO: Storing PKCS #12 password in /root/.dogtag/pki-tomcat/ca/pkcs12_password.conf INFO: Updating /root/.dogtag/pki-tomcat/ca/pkcs12_password.conf DEBUG: Command: chmod 660 /root/.dogtag/pki-tomcat/ca/pkcs12_password.conf DEBUG: Command: chown 17:17 /root/.dogtag/pki-tomcat/ca/pkcs12_password.conf DEBUG: Command: mkdir /root/.dogtag/pki-tomcat/ca/alias DEBUG: Command: certutil -N -d /root/.dogtag/pki-tomcat/ca/alias -f /root/.dogtag/pki-tomcat/ca/password.conf INFO: Creating SELinux contexts INFO: Generating system keys INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /etc/pki/pki-tomcat/tomcat.conf INFO: Loading password config: /etc/pki/pki-tomcat/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser INFO: Configuring subsystem INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /etc/pki/pki-tomcat/tomcat.conf INFO: Loading password config: /etc/pki/pki-tomcat/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Checking existing SSL server cert: Server-Cert cert-pki-ca DEBUG: NSSDatabase.get_cert(Server-Cert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmp4t6jdril/password.txt -n Server-Cert cert-pki-ca -a DEBUG: Cert not found: Server-Cert cert-pki-ca INFO: Creating temp SSL server cert for master.redacted_domain.com DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpfwkckufk/password.txt nss-cert-request --subject cn=master.redacted_domain.com,o=2022-12-18 00:51:31 --csr /tmp/tmplppmpekx/sslserver.csr --key-type RSA --key-size 2048 --hash SHA256 --debug INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Creating RSA key FINE: NSSDatabase: - size: 2048 FINE: CryptoUtil: Generating KRA key pair FINE: CryptoUtil: - extractable: false FINE: CryptoUtil: - sensitive: false FINE: CryptoUtil: - temporary: false FINE: CryptoUtil: - key size: 2048 FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: cn=master.redacted_domain.com,o=2022-12-18 00:51:31 FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: cn=master.redacted_domain.com,o=2022-12-18 00:51:31 FINE: CryptoUtil: - attributes: DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpfwkckufk/password.txt nss-cert-issue --csr /tmp/tmplppmpekx/sslserver.csr --cert /tmp/tmplppmpekx/sslserver.crt --debug INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Issuing cert for CN=master.redacted_domain.com,O=2022-12-18 00:51:31 FINE: NSSDatabase: - issuer: CN=master.redacted_domain.com,O=2022-12-18 00:51:31 FINE: NSSDatabase: - public key algorithm: RSA FINE: NSSDatabase: - serial number: 0x00f323706fc430ecb91700a2b1fddc6f86 FINE: NSSDatabase: - not before: Sun Dec 18 00:51:35 CET 2022 FINE: NSSDatabase: - not after: Sat Mar 18 00:51:35 CET 2023 FINE: NSSDatabase: - hash algorithm: SHA256 FINE: NSSDatabase: - key algorithm: SHA256withRSA FINE: NSSDatabase: Finding request private key FINE: NSSDatabase: - private key: 0xa83a65115903d30fc2f4ba80b4d4477499fc3d76 FINE: NSSDatabase: Private key algorithm: RSA FINE: NSSDatabase: Signing algorithm: SHA256withRSA FINE: CryptoUtil: Signing certificate FINE: CryptoUtil: - signing algorithm: RSASignatureWithSHA256Digest FINE: CryptoUtil: - algorithm name: SHA256withRSA FINE: CryptoUtil: - algorithm ID: SHA256withRSA DEBUG: NSSDatabase.add_cert(Server-Cert cert-pki-ca) DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpfwkckufk/password.txt nss-cert-import --cert /tmp/tmplppmpekx/sslserver.crt --debug Server-Cert cert-pki-ca INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Storing password into /tmp/nss-password-5960273188187234837.txt FINE: NSSDatabase: Command: certutil -A -d /etc/pki/pki-tomcat/alias -f /tmp/nss-password-5960273188187234837.txt -a -n "Server-Cert cert-pki-ca" -t ,, -i /tmp/nss-cert-17468981900684482064.crt INFO: Creating new security domain INFO: Using CA at https://master.redacted_domain.com:443 INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Removing existing database DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-db-remove --force --debug FINE: SubsystemDBRemoveCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Removing database ipaca FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager INFO: Validating database ownership INFO: Validating database ipaca is owned by o=ipaca INFO: Deleting mapping entry cn="o=ipaca",cn=mapping tree, cn=config INFO: Deleting cn="o=ipaca",cn=mapping tree, cn=config INFO: Entry not found: cn="o=ipaca",cn=mapping tree, cn=config INFO: Deleting database entry cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Deleting cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Entry not found: cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Initializing database INFO: - internaldb.ldapconn.port: 389 INFO: - internaldb.ldapconn.secureConn: false DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-db-init --setup-schema --create-database --create-base --create-containers --debug FINE: SubsystemDBInitCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Initializing database ipaca for o=ipaca FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager INFO: Initialize database INFO: Importing /usr/share/pki/server/conf/database.ldif FINE: - database: ipaca FINE: - rootSuffix: o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-11229507485527736463.ldif INFO: Replacing nsslapd-maxbersize in cn=config INFO: Replacing nsslapd-pluginenabled in cn=USN,cn=plugins,cn=config INFO: Adding ou=csusers,cn=config INFO: Setting up PKI schema INFO: Importing /usr/share/pki/server/conf/schema.ldif INFO: Adding attributetypes: ( usertype-oid NAME 'usertype' DESC 'Distinguish whether the user is administrator, agent or subsystem.' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( userstate-oid NAME 'userstate' DESC 'Distinguish whether the user is administrator, agent or subsystem.' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( cmsuser-oid NAME 'cmsuser' DESC 'CMS User' SUP top STRUCTURAL MUST usertype MAY userstate X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( archivedBy-oid NAME 'archivedBy' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( adminMessages-oid NAME 'adminMessages' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( algorithm-oid NAME 'algorithm' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( algorithmId-oid NAME 'algorithmId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( signingAlgorithmId-oid NAME 'signingAlgorithmId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( autoRenew-oid NAME 'autoRenew' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( certStatus-oid NAME 'certStatus' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlName-oid NAME 'crlName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlSize-oid NAME 'crlSize' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( deltaSize-oid NAME 'deltaSize' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlNumber-oid NAME 'crlNumber' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( deltaNumber-oid NAME 'deltaNumber' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( firstUnsaved-oid NAME 'firstUnsaved' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlCache-oid NAME 'crlCache' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( revokedCerts-oid NAME 'revokedCerts' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( unrevokedCerts-oid NAME 'unrevokedCerts' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( expiredCerts-oid NAME 'expiredCerts' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlExtensions-oid NAME 'crlExtensions' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfArchival-oid NAME 'dateOfArchival' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfRecovery-oid NAME 'dateOfRecovery' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfRevocation-oid NAME 'dateOfRevocation' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfCreate-oid NAME 'dateOfCreate' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfModify-oid NAME 'dateOfModify' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( duration-oid NAME 'duration' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( extension-oid NAME 'extension' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( issuedBy-oid NAME 'issuedBy' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( issueInfo-oid NAME 'issueInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( issuerName-oid NAME 'issuerName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( keySize-oid NAME 'keySize' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( clientId-oid NAME 'clientId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dataType-oid NAME 'dataType' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( status-oid NAME 'status' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( keyState-oid NAME 'keyState' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( metaInfo-oid NAME 'metaInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( nextUpdate-oid NAME 'nextUpdate' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( notAfter-oid NAME 'notAfter' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( notBefore-oid NAME 'notBefore' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( ownerName-oid NAME 'ownerName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( password-oid NAME 'password' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( p12Expiration-oid NAME 'p12Expiration' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( proofOfArchival-oid NAME 'proofOfArchival' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( publicKeyData-oid NAME 'publicKeyData' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( publicKeyFormat-oid NAME 'publicKeyFormat' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( privateKeyData-oid NAME 'privateKeyData' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestId-oid NAME 'requestId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestInfo-oid NAME 'requestInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestState-oid NAME 'requestState' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestResult-oid NAME 'requestResult' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestOwner-oid NAME 'requestOwner' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestAgentGroup-oid NAME 'requestAgentGroup' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestSourceId-oid NAME 'requestSourceId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestType-oid NAME 'requestType' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestFlag-oid NAME 'requestFlag' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestError-oid NAME 'requestError' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( resourceACLS-oid NAME 'resourceACLS' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( revInfo-oid NAME 'revInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( revokedBy-oid NAME 'revokedBy' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( revokedOn-oid NAME 'revokedOn' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( serialno-oid NAME 'serialno' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( nextRange-oid NAME 'nextRange' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( publishingStatus-oid NAME 'publishingStatus' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( beginRange-oid NAME 'beginRange' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( endRange-oid NAME 'endRange' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( subjectName-oid NAME 'subjectName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( sessionContext-oid NAME 'sessionContext' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( thisUpdate-oid NAME 'thisUpdate' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( transId-oid NAME 'transId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( transStatus-oid NAME 'transStatus' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( transName-oid NAME 'transName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( transOps-oid NAME 'transOps' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( userDN-oid NAME 'userDN' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( userMessages-oid NAME 'userMessages' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( version-oid NAME 'version' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( Clone-oid NAME 'Clone' SYNTAX 1.3.6.1.4.1.1466.115.121.1.7 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( DomainManager-oid NAME 'DomainManager' SYNTAX 1.3.6.1.4.1.1466.115.121.1.7 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SecurePort-oid NAME 'SecurePort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SecureAgentPort-oid NAME 'SecureAgentPort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SecureAdminPort-oid NAME 'SecureAdminPort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SecureEEClientAuthPort-oid NAME 'SecureEEClientAuthPort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( UnSecurePort-oid NAME 'UnSecurePort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SubsystemName-oid NAME 'SubsystemName' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( cmsUserGroup-oid NAME 'cmsUserGroup' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( realm-oid NAME 'realm' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( CertACLS-oid NAME 'CertACLS' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY resourceACLS X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( repository-oid NAME 'repository' DESC 'CMS defined class' SUP top STRUCTURAL MUST ou MAY ( serialno $ description $ nextRange $ publishingStatus ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( request-oid NAME 'request' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( requestId $ dateOfCreate $ dateOfModify $ requestState $ requestResult $ requestOwner $ requestAgentGroup $ requestSourceId $ requestType $ requestFlag $ requestError $ userMessages $ adminMessages $ realm ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( transaction-oid NAME 'transaction' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( transId $ description $ transName $ transStatus $ transOps ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( crlIssuingPointRecord-oid NAME 'crlIssuingPointRecord' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( dateOfCreate $ dateOfModify $ crlNumber $ crlSize $ thisUpdate $ nextUpdate $ deltaNumber $ deltaSize $ firstUnsaved $ certificateRevocationList $ deltaRevocationList $ crlCache $ revokedCerts $ unrevokedCerts $ expiredCerts $ cACertificate ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( certificateRecord-oid NAME 'certificateRecord' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( serialno $ dateOfCreate $ dateOfModify $ certStatus $ autoRenew $ issueInfo $ metaInfo $ revInfo $ version $ duration $ notAfter $ notBefore $ algorithmId $ subjectName $ signingAlgorithmId $ userCertificate $ issuedBy $ revokedBy $ revokedOn $ extension $ publicKeyData $ issuerName ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( userDetails-oid NAME 'userDetails' DESC 'CMS defined class' SUP top STRUCTURAL MUST userDN MAY ( dateOfCreate $ dateOfModify $ password $ p12Expiration ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( keyRecord-oid NAME 'keyRecord' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( serialno $ dateOfCreate $ dateOfModify $ keyState $ privateKeyData $ ownerName $ keySize $ metaInfo $ dateOfArchival $ dateOfRecovery $ algorithm $ publicKeyFormat $ publicKeyData $ archivedBy $ clientId $ dataType $ status $ realm ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( pkiSecurityDomain-oid NAME 'pkiSecurityDomain' DESC 'CMS defined class' SUP top STRUCTURAL MUST ( ou $ name ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( pkiSecurityGroup-oid NAME 'pkiSecurityGroup' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( pkiSubsystem-oid NAME 'pkiSubsystem' DESC 'CMS defined class' SUP top STRUCTURAL MUST ( cn $ Host $ SecurePort $ SubsystemName $ Clone ) MAY ( DomainManager $ SecureAgentPort $ SecureAdminPort $SecureEEClientAuthPort $ UnSecurePort ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( pkiRange-oid NAME 'pkiRange' DESC 'CMS defined class' SUP top STRUCTURAL MUST ( cn $ beginRange $ endRange $ Host $ SecurePort ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( securityDomainSessionEntry-oid NAME 'securityDomainSessionEntry' DESC 'CMS defined class' SUP top STRUCTURAL MUST ( cn $ host $ uid $ cmsUserGroup $ dateOfCreate ) X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfCreate-oid NAME 'dateOfCreate' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfModify-oid NAME 'dateOfModify' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( modified-oid NAME 'modified' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenUserID-oid NAME 'tokenUserID' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenStatus-oid NAME 'tokenStatus' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenAppletID-oid NAME 'tokenAppletID' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( keyInfo-oid NAME 'keyInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( numberOfResets-oid NAME 'numberOfResets' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( numberOfEnrollments-oid NAME 'numberOfEnrollments' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( numberOfRenewals-oid NAME 'numberOfRenewals' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( numberOfRecoveries-oid NAME 'numberOfRecoveries' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( allowPinReset-oid NAME 'allowPinReset' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( extensions-oid NAME 'extensions' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenOp-oid NAME 'tokenOp' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenID-oid NAME 'tokenID' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenMsg-oid NAME 'tokenMsg' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenResult-oid NAME 'tokenResult' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenIP-oid NAME 'tokenIP' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenPolicy-oid NAME 'tokenPolicy' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenIssuer-oid NAME 'tokenIssuer' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenSubject-oid NAME 'tokenSubject' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenSerial-oid NAME 'tokenSerial' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenOrigin-oid NAME 'tokenOrigin' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenType-oid NAME 'tokenType' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenKeyType-oid NAME 'tokenKeyType' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenReason-oid NAME 'tokenReason' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenNotBefore-oid NAME 'tokenNotBefore' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenNotAfter-oid NAME 'tokenNotAfter' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( profileID-oid NAME 'profileID' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( tokenRecord-oid NAME 'tokenRecord' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( dateOfCreate $ dateOfModify $ modified $ tokenReason $ tokenUserID $ tokenStatus $ tokenAppletID $ keyInfo $ tokenPolicy $ extensions $ numberOfResets $ numberOfEnrollments $ numberOfRenewals $ numberOfRecoveries $ userCertificate $ tokenType ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( tokenActivity-oid NAME 'tokenActivity' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( dateOfCreate $ dateOfModify $ tokenOp $ tokenIP $ tokenResult $ tokenID $ tokenUserID $ tokenMsg $ extensions $ tokenType ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( tokenCert-oid NAME 'tokenCert' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( dateOfCreate $ dateOfModify $ userCertificate $ tokenUserID $ tokenID $ tokenIssuer $ tokenOrigin $ tokenSubject $ tokenSerial $ tokenStatus $ tokenType $ tokenKeyType $ tokenNotBefore $ tokenNotAfter $ extensions ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( tpsProfileID-oid NAME 'tpsProfileID' DESC 'CMS defined class' SUP top AUXILIARY MAY ( profileID ) X-ORIGIN 'user-defined' ) INFO: Adding attributetypes: ( classId-oid NAME 'classId' DESC 'Certificate profile class ID' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( certProfileConfig-oid NAME 'certProfileConfig' DESC 'Certificate profile configuration' SYNTAX 1.3.6.1.4.1.1466.115.121.1.40 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( certProfile-oid NAME 'certProfile' DESC 'Certificate profile' SUP top STRUCTURAL MUST cn MAY ( classId $ certProfileConfig ) X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityID-oid NAME 'authorityID' DESC 'Authority ID' SYNTAX 1.3.6.1.4.1.1466.115.121.1.40 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityKeyNickname-oid NAME 'authorityKeyNickname' DESC 'Authority key nickname' SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE X-ORIGIN 'user-defined' ) INFO: Adding attributetypes: ( authorityParentID-oid NAME 'authorityParentID' DESC 'Authority Parent ID' SYNTAX 1.3.6.1.4.1.1466.115.121.1.40 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityEnabled-oid NAME 'authorityEnabled' DESC 'Authority Enabled' SYNTAX 1.3.6.1.4.1.1466.115.121.1.7 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityDN-oid NAME 'authorityDN' DESC 'Authority DN' SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authoritySerial-oid NAME 'authoritySerial' DESC 'Authority certificate serial number' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityParentDN-oid NAME 'authorityParentDN' DESC 'Authority Parent DN' SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityKeyHost-oid NAME 'authorityKeyHost' DESC 'Authority Key Hosts' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( authority-oid NAME 'authority' DESC 'Certificate Authority' SUP top STRUCTURAL MUST ( cn $ authorityID $ authorityKeyNickname $ authorityEnabled $ authorityDN ) MAY ( authoritySerial $ authorityParentID $ authorityParentDN $ authorityKeyHost $ description ) X-ORIGIN 'user defined' ) INFO: Adding cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn="o=ipaca",cn=mapping tree, cn=config INFO: Adding o=ipaca INFO: Creating container entries INFO: Importing /usr/share/pki/ca/conf/db.ldif FINE: - database: ipaca FINE: - rootSuffix: o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-8897096475419272114.ldif INFO: Adding ou=people,o=ipaca INFO: Adding ou=groups,o=ipaca INFO: Adding cn=Certificate Manager Agents,ou=groups,o=ipaca INFO: Adding cn=Registration Manager Agents,ou=groups,o=ipaca INFO: Adding cn=Subsystem Group, ou=groups, o=ipaca INFO: Adding cn=Trusted Managers,ou=groups,o=ipaca INFO: Adding cn=Administrators,ou=groups,o=ipaca INFO: Adding cn=Auditors,ou=groups,o=ipaca INFO: Adding cn=ClonedSubsystems,ou=groups,o=ipaca INFO: Adding cn=Security Domain Administrators,ou=groups,o=ipaca INFO: Adding cn=Enterprise CA Administrators,ou=groups,o=ipaca INFO: Adding cn=Enterprise KRA Administrators,ou=groups,o=ipaca INFO: Adding cn=Enterprise OCSP Administrators,ou=groups,o=ipaca INFO: Adding cn=Enterprise TKS Administrators,ou=groups,o=ipaca INFO: Adding cn=Enterprise RA Administrators,ou=groups,o=ipaca INFO: Adding cn=Enterprise TPS Administrators,ou=groups,o=ipaca INFO: Adding ou=requests,o=ipaca INFO: Adding cn=crossCerts,o=ipaca INFO: Adding ou=ca,o=ipaca INFO: Adding ou=certificateRepository,ou=ca,o=ipaca INFO: Adding ou=crlIssuingPoints,ou=ca,o=ipaca INFO: Adding ou=ca, ou=requests,o=ipaca INFO: Adding ou=replica,o=ipaca INFO: Adding ou=ranges,o=ipaca INFO: Adding ou=replica, ou=ranges,o=ipaca INFO: Adding ou=requests, ou=ranges,o=ipaca INFO: Adding ou=certificateRepository, ou=ranges,o=ipaca INFO: Adding ou=certificateProfiles,ou=ca,o=ipaca INFO: Adding ou=authorities,ou=ca,o=ipaca INFO: Setting up ACL INFO: Importing /usr/share/pki/ca/conf/acl.ldif FINE: - database: ipaca FINE: - rootSuffix: o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-2856455432900238518.ldif INFO: Adding cn=aclResources,o=ipaca INFO: Creating indexes INFO: Importing /usr/share/pki/ca/conf/index.ldif FINE: - database: ipaca FINE: - rootSuffix: o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-8697363272773283469.ldif INFO: Adding cn=revokedby,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=issuedby,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=publicKeyData,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=clientId,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=dataType,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=status,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=description,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=serialno,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=metaInfo,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=certstatus,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=requestid,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=requesttype,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=requeststate,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=requestowner,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=notbefore,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=notafter,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=duration,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=dateOfCreate,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=revokedOn,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=archivedBy,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=ownername,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=issuername,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=subjectname,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=requestsourceid,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=revInfo,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=extension,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=acmeExpires,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=acmeAccountId,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=acmeStatus,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=acmeAuthorizationId,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=acmeIdentifier,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=acmeCertificateId,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=acmeAuthorizationWildcard,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-db-access-grant --debug uid=pkidbuser,ou=people,o=ipaca FINE: SubsystemDBAccessGrantCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager INFO: Granting database access to uid=pkidbuser,ou=people,o=ipaca INFO: Importing /usr/share/pki/server/conf/db-access-grant.ldif FINE: - dbuser: uid=pkidbuser,ou=people,o=ipaca FINE: - database: ipaca FINE: - rootSuffix: o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-18136538482551054562.ldif INFO: Adding aci into o=ipaca INFO: Adding aci into cn=ldbm database,cn=plugins,cn=config INFO: Adding aci into cn=config INFO: Adding aci into ou=csusers,cn=config INFO: Adding aci into cn="o=ipaca",cn=mapping tree,cn=config INFO: Adding aci into cn="o=ipaca",cn=mapping tree,cn=config INFO: Adding aci into cn="o=ipaca",cn=mapping tree,cn=config INFO: Adding aci into cn=tasks,cn=config DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-db-vlv-add --debug FINE: SubsystemDBVLVAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager INFO: Add VLVs INFO: Importing /usr/share/pki/ca/conf/vlv.ldif FINE: - database: ipaca FINE: - instanceId: pki-tomcat FINE: - rootSuffix: o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-279253781897190379.ldif INFO: Adding cn=allCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allExpiredCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allInvalidCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allInValidCertsNotBefore-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allNonRevokedCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedCaCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedCertsNotAfter-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedExpiredCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedOrRevokedExpiredCaCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedOrRevokedExpiredCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allValidCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allValidCertsNotAfter-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allValidOrRevokedCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caAll-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceled-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceledEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceledRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceledRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caComplete-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCompleteEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCompleteRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCompleteRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPending-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPendingEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPendingRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPendingRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejected-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejectedEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejectedRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejectedRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allCerts-pki-tomcatIndex, cn=allCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allExpiredCerts-pki-tomcatIndex, cn=allExpiredCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allInvalidCerts-pki-tomcatIndex, cn=allInvalidCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allInValidCertsNotBefore-pki-tomcatIndex, cn=allInValidCertsNotBefore-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allNonRevokedCerts-pki-tomcatIndex, cn=allNonRevokedCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedCaCerts-pki-tomcatIndex, cn=allRevokedCaCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedCerts-pki-tomcatIndex, cn=allRevokedCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedCertsNotAfter-pki-tomcatIndex, cn=allRevokedCertsNotAfter-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedExpiredCerts-pki-tomcatIndex, cn=allRevokedExpiredCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedOrRevokedExpiredCaCerts-pki-tomcatIndex, cn=allRevokedOrRevokedExpiredCaCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allRevokedOrRevokedExpiredCerts-pki-tomcatIndex, cn=allRevokedOrRevokedExpiredCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allValidCerts-pki-tomcatIndex, cn=allValidCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allValidCertsNotAfter-pki-tomcatIndex, cn=allValidCertsNotAfter-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allValidOrRevokedCerts-pki-tomcatIndex, cn=allValidOrRevokedCerts-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caAll-pki-tomcatIndex, cn=caAll-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceled-pki-tomcatIndex, cn=caCanceled-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceledEnrollment-pki-tomcatIndex, cn=caCanceledEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceledRenewal-pki-tomcatIndex, cn=caCanceledRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCanceledRevocation-pki-tomcatIndex, cn=caCanceledRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caComplete-pki-tomcatIndex, cn=caComplete-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCompleteEnrollment-pki-tomcatIndex, cn=caCompleteEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCompleteRenewal-pki-tomcatIndex, cn=caCompleteRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caCompleteRevocation-pki-tomcatIndex, cn=caCompleteRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caEnrollment-pki-tomcatIndex, cn=caEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPending-pki-tomcatIndex, cn=caPending-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPendingEnrollment-pki-tomcatIndex, cn=caPendingEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPendingRenewal-pki-tomcatIndex, cn=caPendingRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caPendingRevocation-pki-tomcatIndex, cn=caPendingRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejected-pki-tomcatIndex, cn=caRejected-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejectedEnrollment-pki-tomcatIndex, cn=caRejectedEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejectedRenewal-pki-tomcatIndex, cn=caRejectedRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRejectedRevocation-pki-tomcatIndex, cn=caRejectedRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRenewal-pki-tomcatIndex, cn=caRenewal-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=caRevocation-pki-tomcatIndex, cn=caRevocation-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-db-vlv-reindex --debug FINE: SubsystemDBVLVReindexCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager INFO: Reindex VLVs INFO: Importing /usr/share/pki/ca/conf/vlvtasks.ldif FINE: - database: ipaca FINE: - instanceId: pki-tomcat FINE: - rootSuffix: o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-16686519815822735500.ldif INFO: Adding cn=index1160589769, cn=index, cn=tasks, cn=config INFO: Waiting for task cn=index1160589769, cn=index, cn=tasks, cn=config (1s) INFO: Getting cn=index1160589769, cn=index, cn=tasks, cn=config INFO: Task cn=index1160589769, cn=index, cn=tasks, cn=config complete INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-profile-import --input-folder /usr/share/pki/ca/profiles/ca --debug INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/conf/ca/registry.cfg INFO: PluginRegistry: Loading plugin registry from /var/lib/pki/pki-tomcat/conf/ca/registry.cfg FINE: PluginRegistry: profile: FINE: PluginRegistry: - caEnrollImpl FINE: PluginRegistry: Added plugin profile caEnrollImpl Generic Certificate Enrollment Profile Certificate Authority Generic Certificate Enrollment Profile com.netscape.cms.profile.common.CAEnrollProfile FINE: PluginRegistry: - caCACertEnrollImpl FINE: PluginRegistry: Added plugin profile caCACertEnrollImpl CA Certificate Enrollment Profile Certificate Authority CA Certificate Enrollment Profile com.netscape.cms.profile.common.CACertCAEnrollProfile FINE: PluginRegistry: - caServerCertEnrollImpl FINE: PluginRegistry: Added plugin profile caServerCertEnrollImpl Server Certificate Enrollment Profile Certificate Authority Server Certificate Enrollment Profile com.netscape.cms.profile.common.ServerCertCAEnrollProfile FINE: PluginRegistry: - caUserCertEnrollImpl FINE: PluginRegistry: Added plugin profile caUserCertEnrollImpl User Certificate Enrollment Profile Certificate Authority User Certificate Enrollment Profile com.netscape.cms.profile.common.UserCertCAEnrollProfile FINE: PluginRegistry: defaultPolicy: FINE: PluginRegistry: - noDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy noDefaultImpl No Default No Default com.netscape.cms.profile.def.NoDefault FINE: PluginRegistry: - genericExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy genericExtDefaultImpl Generic Extension Generic Extension com.netscape.cms.profile.def.GenericExtDefault FINE: PluginRegistry: - autoAssignDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy autoAssignDefaultImpl Auto Request Assignment Default Auto Request Assignment Default com.netscape.cms.profile.def.AutoAssignDefault FINE: PluginRegistry: - subjectNameDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy subjectNameDefaultImpl Subject Name Default Subject Name Default com.netscape.cms.profile.def.SubjectNameDefault FINE: PluginRegistry: - validityDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy validityDefaultImpl Validity Default Validty Default com.netscape.cms.profile.def.ValidityDefault FINE: PluginRegistry: - randomizedValidityDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy randomizedValidityDefaultImpl Randomized Validity Default Randomized Validity Default com.netscape.cms.profile.def.RandomizedValidityDefault FINE: PluginRegistry: - caValidityDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy caValidityDefaultImpl CA Certificate Validity Default CA Certificate Validty Default com.netscape.cms.profile.def.CAValidityDefault FINE: PluginRegistry: - subjectKeyIdentifierExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy subjectKeyIdentifierExtDefaultImpl Subject Key Identifier Default Subject Key Identifier Default com.netscape.cms.profile.def.SubjectKeyIdentifierExtDefault FINE: PluginRegistry: - authorityKeyIdentifierExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy authorityKeyIdentifierExtDefaultImpl Authority Key Identifier Extension Default Authority Key Identifier Extension Default com.netscape.cms.profile.def.AuthorityKeyIdentifierExtDefault FINE: PluginRegistry: - basicConstraintsExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy basicConstraintsExtDefaultImpl Basic Constraints Extension Default Basic Constraints Extension Default com.netscape.cms.profile.def.BasicConstraintsExtDefault FINE: PluginRegistry: - keyUsageExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy keyUsageExtDefaultImpl Key Usage Extension Default Key Usage Extension Default com.netscape.cms.profile.def.KeyUsageExtDefault FINE: PluginRegistry: - nsCertTypeExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy nsCertTypeExtDefaultImpl Netscape Certificate Type Extension Default Netscape Certificate Type Extension Default com.netscape.cms.profile.def.NSCertTypeExtDefault FINE: PluginRegistry: - extendedKeyUsageExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy extendedKeyUsageExtDefaultImpl Extended Key Usage Extension Default Extended Key Usage Extension Default com.netscape.cms.profile.def.ExtendedKeyUsageExtDefault FINE: PluginRegistry: - ocspNoCheckExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy ocspNoCheckExtDefaultImpl OCSP No Check Extension Default OCSP No Check Extension Default com.netscape.cms.profile.def.OCSPNoCheckExtDefault FINE: PluginRegistry: - issuerAltNameExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy issuerAltNameExtDefaultImpl Issuer Alternative Name Extension Default Issuer Alternative Name Extension Default com.netscape.cms.profile.def.IssuerAltNameExtDefault FINE: PluginRegistry: - subjectAltNameExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy subjectAltNameExtDefaultImpl Subject Alternative Name Extension Default Subject Alternative Name Extension Default com.netscape.cms.profile.def.SubjectAltNameExtDefault FINE: PluginRegistry: - userSubjectNameDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy userSubjectNameDefaultImpl User Supplied Subject Name Default User Supplied Subject Name Default com.netscape.cms.profile.def.UserSubjectNameDefault FINE: PluginRegistry: - cmcUserSignedSubjectNameDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy cmcUserSignedSubjectNameDefaultImpl CMC User Signed Subject Name Default CMC User Signed Subject Name Default com.netscape.cms.profile.def.CMCUserSignedSubjectNameDefault FINE: PluginRegistry: - signingAlgDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy signingAlgDefaultImpl Signing Algorithm Default Signing Algorithm Default com.netscape.cms.profile.def.SigningAlgDefault FINE: PluginRegistry: - userKeyDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy userKeyDefaultImpl User Supplied Key Default User Supplied Key Default com.netscape.cms.profile.def.UserKeyDefault FINE: PluginRegistry: - userValidityDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy userValidityDefaultImpl User Supplied Validity Default User Supplied Validity Default com.netscape.cms.profile.def.UserValidityDefault FINE: PluginRegistry: - userExtensionDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy userExtensionDefaultImpl User Supplied Extension Default User Supplied Extension Default com.netscape.cms.profile.def.UserExtensionDefault FINE: PluginRegistry: - userSigningAlgDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy userSigningAlgDefaultImpl User Supplied Signing Alg Default User Supplied Signing Alg Default com.netscape.cms.profile.def.UserSigningAlgDefault FINE: PluginRegistry: - authTokenSubjectNameDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy authTokenSubjectNameDefaultImpl Token Supplied Subject Name Default Token Supplied Subject Name Default com.netscape.cms.profile.def.AuthTokenSubjectNameDefault FINE: PluginRegistry: - subjectInfoAccessExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy subjectInfoAccessExtDefaultImpl Subject Info Access Extension Default Subject Info Access Extension Default com.netscape.cms.profile.def.SubjectInfoAccessExtDefault FINE: PluginRegistry: - authInfoAccessExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy authInfoAccessExtDefaultImpl Authority Info Access Extension Default Authority Info Access Extension Default com.netscape.cms.profile.def.AuthInfoAccessExtDefault FINE: PluginRegistry: - nscCommentExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy nscCommentExtDefaultImpl Netscape Comment Extension Default Netscape Comment Extension Default com.netscape.cms.profile.def.NSCCommentExtDefault FINE: PluginRegistry: - freshestCRLExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy freshestCRLExtDefaultImpl Freshest CRL Extension Default Freshest CRL Extension Default com.netscape.cms.profile.def.FreshestCRLExtDefault FINE: PluginRegistry: - crlDistributionPointsExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy crlDistributionPointsExtDefaultImpl CRL Distribution Points Extension Default CRL Distribution Points Extension Default com.netscape.cms.profile.def.CRLDistributionPointsExtDefault FINE: PluginRegistry: - policyConstraintsExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy policyConstraintsExtDefaultImpl Policy Constraints Extension Default Policy Constraints Extension Default com.netscape.cms.profile.def.PolicyConstraintsExtDefault FINE: PluginRegistry: - policyMappingsExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy policyMappingsExtDefaultImpl Policy Mappings Extension Default Policy Mappings Extension Default com.netscape.cms.profile.def.PolicyMappingsExtDefault FINE: PluginRegistry: - nameConstraintsExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy nameConstraintsExtDefaultImpl Name Constraints Extension Default Name Constraints Extension Default com.netscape.cms.profile.def.NameConstraintsExtDefault FINE: PluginRegistry: - certificateVersionDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy certificateVersionDefaultImpl Certificate Version Default Certificate Version Default com.netscape.cms.profile.def.CertificateVersionDefault FINE: PluginRegistry: - certificatePoliciesExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy certificatePoliciesExtDefaultImpl Certificate Policies Extension Default Certificate Policies Extension Default com.netscape.cms.profile.def.CertificatePoliciesExtDefault FINE: PluginRegistry: - subjectDirAttributesExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy subjectDirAttributesExtDefaultImpl Subject Directory Attributes Extension Default Subject Directory Attributes Extension Default com.netscape.cms.profile.def.SubjectDirAttributesExtDefault FINE: PluginRegistry: - privateKeyPeriodExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy privateKeyPeriodExtDefaultImpl Private Key Period Ext Default Private Key Period Ext Default com.netscape.cms.profile.def.PrivateKeyUsagePeriodExtDefault FINE: PluginRegistry: - inhibitAnyPolicyExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy inhibitAnyPolicyExtDefaultImpl Inhibit Any-Policy Extension Default Inhibit Any-Policy Extension Default com.netscape.cms.profile.def.InhibitAnyPolicyExtDefault FINE: PluginRegistry: - imageDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy imageDefaultImpl Image Default Image Default com.netscape.cms.profile.def.ImageDefault FINE: PluginRegistry: - nsTokenDeviceKeySubjectNameDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy nsTokenDeviceKeySubjectNameDefaultImpl nsTokenDeviceKeySubjectNameDefault nsTokenDeviceKeySubjectNameDefaultImpl com.netscape.cms.profile.def.nsTokenDeviceKeySubjectNameDefault FINE: PluginRegistry: - nsTokenUserKeySubjectNameDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy nsTokenUserKeySubjectNameDefaultImpl nsTokenUserKeySubjectNameDefault nsTokenUserKeySubjectNameDefaultImpl com.netscape.cms.profile.def.nsTokenUserKeySubjectNameDefault FINE: PluginRegistry: - authzRealmDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy authzRealmDefaultImpl Authz Realm Default Authz Realm Default com.netscape.cms.profile.def.AuthzRealmDefault FINE: PluginRegistry: - commonNameToSANDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy commonNameToSANDefaultImpl Copy Common Name to Subject Alternative Name Copy Common Name to Subject Alternative Name com.netscape.cms.profile.def.CommonNameToSANDefault FINE: PluginRegistry: - SignedCertificateTimestampListExtDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy SignedCertificateTimestampListExtDefaultImpl Certificate Transparency Timestamp List Extension Default Certificate Transparency Timestamp List Extension Default com.netscape.cms.profile.def.SignedCertificateTimestampListExtDefault FINE: PluginRegistry: - sanToCNDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy sanToCNDefaultImpl SAN to CN Default SAN to CN Default com.netscape.cms.profile.def.SANToCNDefault FINE: PluginRegistry: - serverKeygenUserKeyDefaultImpl FINE: PluginRegistry: Added plugin defaultPolicy serverKeygenUserKeyDefaultImpl Server-Side Keygen Default Server-Side Keygen Default com.netscape.cms.profile.def.ServerKeygenUserKeyDefault FINE: PluginRegistry: constraintPolicy: FINE: PluginRegistry: - noConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy noConstraintImpl No Constraint No Constraint com.netscape.cms.profile.constraint.NoConstraint FINE: PluginRegistry: - subjectNameConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy subjectNameConstraintImpl Subject Name Constraint Subject Name Constraint com.netscape.cms.profile.constraint.SubjectNameConstraint FINE: PluginRegistry: - uniqueSubjectNameConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy uniqueSubjectNameConstraintImpl Unique Subject Name Constraint Unique Subject Name Constraint com.netscape.cms.profile.constraint.UniqueSubjectNameConstraint FINE: PluginRegistry: - userSubjectNameConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy userSubjectNameConstraintImpl User Subject Name Constraint User Subject Name Constraint com.netscape.cms.profile.constraint.UserSubjectNameConstraint FINE: PluginRegistry: - cmcSharedTokenSubjectNameConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy cmcSharedTokenSubjectNameConstraintImpl CMC Shared Token request User Subject Name Constraint CMC Shared Token request User Subject Name Constraint com.netscape.cms.profile.constraint.CMCSharedTokenSubjectNameConstraint FINE: PluginRegistry: - cmcUserSignedSubjectNameConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy cmcUserSignedSubjectNameConstraintImpl CMC User-Signed request User Subject Name Constraint CMC User-Signed request User Subject Name Constraint com.netscape.cms.profile.constraint.CMCUserSignedSubjectNameConstraint FINE: PluginRegistry: - caValidityConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy caValidityConstraintImpl CA Validity Constraint CA Validity Constraint com.netscape.cms.profile.constraint.CAValidityConstraint FINE: PluginRegistry: - validityConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy validityConstraintImpl Validity Constraint Validity Constraint com.netscape.cms.profile.constraint.ValidityConstraint FINE: PluginRegistry: - keyUsageExtConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy keyUsageExtConstraintImpl Key Usage Extension Constraint Key Usage Extension Constraint com.netscape.cms.profile.constraint.KeyUsageExtConstraint FINE: PluginRegistry: - nsCertTypeExtConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy nsCertTypeExtConstraintImpl Netscape Certificate Type Extension Constraint Netscape Certificate Type Extension Constraint com.netscape.cms.profile.constraint.NSCertTypeExtConstraint FINE: PluginRegistry: - extendedKeyUsageExtConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy extendedKeyUsageExtConstraintImpl Extended Key Usage Extension Constraint Extended Key Usage Extension Constraint com.netscape.cms.profile.constraint.ExtendedKeyUsageExtConstraint FINE: PluginRegistry: - keyConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy keyConstraintImpl Key Constraint Key Constraint com.netscape.cms.profile.constraint.KeyConstraint FINE: PluginRegistry: - basicConstraintsExtConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy basicConstraintsExtConstraintImpl Basic Constraints Extension Constraint Basic Constraints Extension Constraint com.netscape.cms.profile.constraint.BasicConstraintsExtConstraint FINE: PluginRegistry: - extensionConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy extensionConstraintImpl Extension Constraint Extension Constraint com.netscape.cms.profile.constraint.ExtensionConstraint FINE: PluginRegistry: - signingAlgConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy signingAlgConstraintImpl Signing Algorithm Constraint Signing Algorithm Constraint com.netscape.cms.profile.constraint.SigningAlgConstraint FINE: PluginRegistry: - uniqueKeyConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy uniqueKeyConstraintImpl Unique Public Key Constraint Unique Public Key Constraint com.netscape.cms.profile.constraint.UniqueKeyConstraint FINE: PluginRegistry: - renewGracePeriodConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy renewGracePeriodConstraintImpl Renewal Grace Period Constraint Renewal Grace Period Constraint com.netscape.cms.profile.constraint.RenewGracePeriodConstraint FINE: PluginRegistry: - authzRealmConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy authzRealmConstraintImpl Authz Realm Constraint Authz Realm Constraint com.netscape.cms.profile.constraint.AuthzRealmConstraint FINE: PluginRegistry: - externalProcessConstraintImpl FINE: PluginRegistry: Added plugin constraintPolicy externalProcessConstraintImpl External Process Constraint External Process Constraint com.netscape.cms.profile.constraint.ExternalProcessConstraint FINE: PluginRegistry: profileInput: FINE: PluginRegistry: - cmcCertReqInputImpl FINE: PluginRegistry: Added plugin profileInput cmcCertReqInputImpl CMC Certificate Request Input CMC Certificate Request Input com.netscape.cms.profile.input.CMCCertReqInput FINE: PluginRegistry: - certReqInputImpl FINE: PluginRegistry: Added plugin profileInput certReqInputImpl Certificate Request Input Certificate Request Input com.netscape.cms.profile.input.CertReqInput FINE: PluginRegistry: - keyGenInputImpl FINE: PluginRegistry: Added plugin profileInput keyGenInputImpl Key Generation Input Key Generation Input com.netscape.cms.profile.input.KeyGenInput FINE: PluginRegistry: - encKeyGenInputImpl FINE: PluginRegistry: Added plugin profileInput encKeyGenInputImpl Encryption Key Generation Input Encryption Key Generation Input com.netscape.cms.profile.input.EncryptionKeyGenInput FINE: PluginRegistry: - signKeyGenInputImpl FINE: PluginRegistry: Added plugin profileInput signKeyGenInputImpl Encryption Key Generation Input Encryption Key Generation Input com.netscape.cms.profile.input.SigningKeyGenInput FINE: PluginRegistry: - dualKeyGenInputImpl FINE: PluginRegistry: Added plugin profileInput dualKeyGenInputImpl Dual Key Generation Input Dual Key Generation Input com.netscape.cms.profile.input.DualKeyGenInput FINE: PluginRegistry: - subjectNameInputImpl FINE: PluginRegistry: Added plugin profileInput subjectNameInputImpl Subject Name Input Subject Name Input com.netscape.cms.profile.input.SubjectNameInput FINE: PluginRegistry: - submitterInfoInputImpl FINE: PluginRegistry: Added plugin profileInput submitterInfoInputImpl Submitter Information Input Submitter Information Input com.netscape.cms.profile.input.SubmitterInfoInput FINE: PluginRegistry: - genericInputImpl FINE: PluginRegistry: Added plugin profileInput genericInputImpl Generic Input Generic Input com.netscape.cms.profile.input.GenericInput FINE: PluginRegistry: - fileSigningInputImpl FINE: PluginRegistry: Added plugin profileInput fileSigningInputImpl File Signing Input File Signing Input com.netscape.cms.profile.input.FileSigningInput FINE: PluginRegistry: - imageInputImpl FINE: PluginRegistry: Added plugin profileInput imageInputImpl Image Input Image Input com.netscape.cms.profile.input.ImageInput FINE: PluginRegistry: - subjectDNInputImpl FINE: PluginRegistry: Added plugin profileInput subjectDNInputImpl Subject DN Input Subject DN Input com.netscape.cms.profile.input.SubjectDNInput FINE: PluginRegistry: - nsNKeyCertReqInputImpl FINE: PluginRegistry: Added plugin profileInput nsNKeyCertReqInputImpl nsNKeyCertReqInputImpl nsNKeyCertReqInputImpl com.netscape.cms.profile.input.nsNKeyCertReqInput FINE: PluginRegistry: - nsHKeyCertReqInputImpl FINE: PluginRegistry: Added plugin profileInput nsHKeyCertReqInputImpl nsHKeyCertReqInputImpl nsHKeyCertReqInputImpl com.netscape.cms.profile.input.nsHKeyCertReqInput FINE: PluginRegistry: - serialNumRenewInputImpl FINE: PluginRegistry: Added plugin profileInput serialNumRenewInputImpl Certificate Renewal Request Serial Number Input Certificate Renewal Request Serial Number Input com.netscape.cms.profile.input.SerialNumRenewInput FINE: PluginRegistry: - subjectAltNameExtInputImpl FINE: PluginRegistry: Added plugin profileInput subjectAltNameExtInputImpl SAN Input SAN Input com.netscape.cms.profile.input.SubjectAltNameExtInput FINE: PluginRegistry: - serverKeygenInputImpl FINE: PluginRegistry: Added plugin profileInput serverKeygenInputImpl Server-Side Keygen Input Server-Side Keygen Input com.netscape.cms.profile.input.ServerKeygenInput FINE: PluginRegistry: profileOutput: FINE: PluginRegistry: - certOutputImpl FINE: PluginRegistry: Added plugin profileOutput certOutputImpl Certificate Output Certificate Output com.netscape.cms.profile.output.CertOutput FINE: PluginRegistry: - cmmfOutputImpl FINE: PluginRegistry: Added plugin profileOutput cmmfOutputImpl CMMF Response Output CMMF Response Output com.netscape.cms.profile.output.CMMFOutput FINE: PluginRegistry: - pkcs7OutputImpl FINE: PluginRegistry: Added plugin profileOutput pkcs7OutputImpl PKCS7 Output PKCS7 Output com.netscape.cms.profile.output.PKCS7Output FINE: PluginRegistry: - nsNKeyOutputImpl FINE: PluginRegistry: Added plugin profileOutput nsNKeyOutputImpl nsNKeyOutputImpl nsNKeyOutputImpl com.netscape.cms.profile.output.nsNKeyOutput FINE: PluginRegistry: - pkcs12OutputImpl FINE: PluginRegistry: Added plugin profileOutput pkcs12OutputImpl PKCS12 Output PKCS12 Output com.netscape.cms.profile.output.PKCS12Output FINE: PluginRegistry: profileUpdater: FINE: PluginRegistry: - subsystemGroupUpdaterImpl FINE: PluginRegistry: Added plugin profileUpdater subsystemGroupUpdaterImpl Updater for Subsystem Group Updater for Subsystem Group com.netscape.cms.profile.updater.SubsystemGroupUpdater FINE: RegistrySubsystem: startup FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager INFO: Importing profiles into LDAP INFO: Importing /usr/share/pki/ca/profiles/ca/acmeServerCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCserverCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCECserverCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCECsubsystemCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCsubsystemCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCauditSigningCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCcaCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCocspCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCkraTransportCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCkraStorageCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caServerKeygen_UserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caServerKeygen_DirUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caECUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caUserSMIMEcapCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caDualCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caDirBasedDualCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/AdminCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/ECAdminCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caSignedLogCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caTPSCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caRARouterCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caRouterCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caServerCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caECServerCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caServerCertWithSCT.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caECServerCertWithSCT.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caSubsystemCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caECSubsystemCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caOtherCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCACert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCcaCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCrossSignedCACert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caInstallCACert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caRACert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caOCSPCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caStorageCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caTransportCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caDirPinUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caECDirPinUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caDirUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caECDirUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caAgentServerCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caECAgentServerCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caAgentFileSigning.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCECUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caCMCcaIssuanceProtectionCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caFullCMCUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caECFullCMCUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caFullCMCUserSignedCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caECFullCMCUserSignedCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caFullCMCSharedTokenCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caECFullCMCSharedTokenCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caSimpleCMCUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caECSimpleCMCUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenDeviceKeyEnrollment.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenUserEncryptionKeyEnrollment.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenUserSigningKeyEnrollment.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caTempTokenDeviceKeyEnrollment.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caTempTokenUserEncryptionKeyEnrollment.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caTempTokenUserSigningKeyEnrollment.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caAdminCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caECAdminCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caInternalAuthServerCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caECInternalAuthServerCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caInternalAuthTransportCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caInternalAuthDRMstorageCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caInternalAuthSubsystemCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caECInternalAuthSubsystemCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caInternalAuthOCSPCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caInternalAuthAuditSigningCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/DomainController.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caDualRAuserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caRAagentCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caRAserverCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caUUIDdeviceCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caSSLClientSelfRenewal.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caDirUserRenewal.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caManualRenewal.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenMSLoginEnrollment.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenUserSigningKeyRenewal.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenUserEncryptionKeyRenewal.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenUserAuthKeyRenewal.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caJarSigningCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caIPAserviceCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caAuditSigningCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caEncUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caSigningUserCert.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenUserDelegateAuthKeyEnrollment.cfg INFO: Importing /usr/share/pki/ca/profiles/ca/caTokenUserDelegateSigningKeyEnrollment.cfg INFO: Enabling CA subsystem INFO: Creating /etc/pki/pki-tomcat/Catalina/localhost/ca.xml INFO: Starting PKI server DEBUG: Command: systemctl start pki-tomcatd@pki-tomcat.service INFO: Waiting for PKI server to start INFO: Waiting for PKI server to start (1s) INFO: PKI server started INFO: Waiting for CA subsystem INFO: Subsystem status: running DEBUG: PKIDeployer.setup_system_certs() INFO: Setting up signing cert DEBUG: PKISubsystem.get_subsystem_cert(signing) INFO: Getting signing cert info from CS.cfg DEBUG: PKISubsystem.get_nssdb_cert_info(signing) INFO: Getting signing cert info from NSS database DEBUG: NSSDatabase.get_cert_info(caSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(caSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmp111h8fa6/password.txt -n caSigningCert cert-pki-ca -a DEBUG: Cert not found: caSigningCert cert-pki-ca DEBUG: PKIDeployer.setup_system_cert() DEBUG: NSSDatabase.get_cert_info(caSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(caSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmp6o8_d2ki/password.txt -n caSigningCert cert-pki-ca -a DEBUG: Cert not found: caSigningCert cert-pki-ca INFO: signing cert does not exist in NSS database INFO: Creating signing key DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpti0wky2e/password.txt nss-key-create --output-format json --key-type RSA --key-size 3072 --debug INFO: - key ID: 0x444c1b001a5161f554c7ac19fd4f1b042f84780f INFO: Creating signing cert request DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpa2iyzx3x/password.txt nss-cert-request --subject CN=Certificate Authority,O=REDACTED_DOMAIN.COM --csr /tmp/tmpsaykfikd/request.csr --key-id 0x444c1b001a5161f554c7ac19fd4f1b042f84780f --hash SHA256 --ext /tmp/tmp_7roql7o/request.conf --debug INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Loading key 0x444c1b001a5161f554c7ac19fd4f1b042f84780f FINE: NSSDatabase: - class: org.mozilla.jss.pkcs11.PK11RSAPrivateKey FINE: NSSDatabase: - algorithm: RSA FINE: NSSDatabase: - format: null FINE: NSSDatabase: - key type: RSA FINE: NSSDatabase: - size: 3072 INFO: Creating basic constraint extension: INFO: - critical INFO: - CA: true INFO: Creating key usage extension: INFO: - critical INFO: - digitalSignature INFO: - nonRepudiation INFO: - keyCertSign INFO: - cRLSign FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: CN=Certificate Authority,O=REDACTED_DOMAIN.COM FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: CN=Certificate Authority,O=REDACTED_DOMAIN.COM FINE: CryptoUtil: - attributes: FINE: CryptoUtil: - extensions DEBUG: - request: MIIDsTCCAhkCAQAwOjEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMR4wHAYDVQQDDBVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQCm+Qr3a2aB/qDNzti8Q4p4wgza8DiJv9plgaM0D+uzoooApz1kDdZaL+OaKyRcIDqKJ0pfQQQG2XBiIL+aZFXkIbrX8kbuzrw4rRIjEdCLQuLbIqtt4aMWVy94m4zRtpMZLdsD33mVuKoY18o2XUugsZMmztA8D80CFfrGpMP3Vbfm55g7yfkbasCWDJAAYa8Ge0V5l4fq0DgOtmQfMGBJ79hmSWUA3iEnRA6IEe+JtJiO+8cT9eEgtNnlmQ93FlDx/0vBgfu/yYQuYbYGNf2KkTdCAG5nUX6e2YcbJfrxF4XaPwyr3wlrWvzxTGDsF6XLUYIW03XzzenAzxxgfvzot43kQtpHVQ/OscKpYmzk/VoYVxS1pUeElXVOsD2J9d2P0s7JRWsFHOOOrKwthQH07V/zWpcZnA4XYzLrTc8I3rClBPENQs2OJIfugMZMhnfSfnN/RftagGmu9xMfeE/bcLMlS4gq+AO0vKLAkhUGVsF4RRr8e0GbnkfGZgMEaKECAwEAAaAyMDAGCSqGSIb3DQEJDjEjMCEwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAcYwDQYJKoZIhvcNAQELBQADggGBAEovuaqIPqMhouMo1+T0EQnrSf5m49cl9gCcx2C8KOeHvUcdVPo4cF0fjOiBHb61FtnXX1jY6nXWdYpoT6X9/ibt6khQ1e1Bxuqj1991qHzhO80rxIEOHqmSIZfTXhGi4ng/H+TSJg+ZZ6FcDWmqgIxcqqexsTUY417ePZiVNDwBVgSWeRubtb3Hf9koR2M3W7mzPfeI9A2XhrXr4vk0SvAxPSacyI5+ky4oLkhmbtpAc5JhWlVh4tWYGQG92cTiiACQ87zf/TUo6GlOPWMO23xWV8uVL2+0Qwx8npgSpNVRzHX3dqvzJu1AqjwOtibKz51/eEl2jIbwHhgoL9AWjKD27UDHNfW3RGOSb7cR7iP4q25qMAKjcI6sgdHKPeMOSY08rV58TmygSM9Xt44yjZnuCT5SQIg4IhL3N00x2DaTow23sba1QlBS+BJcnowGTTcQba8rxLk6UqYJoRkEPStQGkCxREXUeNzsCg/JujA6a1HMiiB+8dTvyO86p9g+9Q== INFO: Creating request ID for signing cert /usr/lib/python3.11/site-packages/urllib3/connection.py:458: SubjectAltNameWarning: Certificate for master.redacted_domain.com has no `subjectAltName`, falling back to check for a `commonName` for now. This feature is being removed by major browsers and deprecated by RFC 2818. (See https://github.com/urllib3/urllib3/issues/497 for details.) warnings.warn( INFO: - request ID: 0x1 INFO: Importing request for signing cert DEBUG: Command: /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-request-import --debug --csr /tmp/tmp3movc4m1/cert.csr --type pkcs10 --profile caCert.profile --output-format json 0x1 INFO: Importing /tmp/tmp3movc4m1/cert.csr INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/caCert.profile FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: Setting internaldb.basedn=o=ipaca FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(true) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: registered: false FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: null FINE: RequestRepository: - range DN: ou=requests,ou=ranges,o=ipaca FINE: RequestRepository: - min serial: 1 FINE: RequestRepository: - max serial: 10000000 FINE: RequestRepository: - next min serial: null FINE: RequestRepository: - next max serial: null FINE: CertRequestRepository: Creating request 0x1 FINE: CertRequestRepository: Updating request 0x1 FINE: CertRequestRepository: - type: pkcs10 FINE: CertRequestRepository: - request: -----BEGIN CERTIFICATE REQUEST----- MIIDsTCCAhkCAQAwOjEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMR4wHAYDVQQDDBVDZXJ0aWZp Y2F0ZSBBdXRob3JpdHkwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQCm+Qr3a2aB/qDN zti8Q4p4wgza8DiJv9plgaM0D+uzoooApz1kDdZaL+OaKyRcIDqKJ0pfQQQG2XBiIL+aZFXkIbrX 8kbuzrw4rRIjEdCLQuLbIqtt4aMWVy94m4zRtpMZLdsD33mVuKoY18o2XUugsZMmztA8D80CFfrG pMP3Vbfm55g7yfkbasCWDJAAYa8Ge0V5l4fq0DgOtmQfMGBJ79hmSWUA3iEnRA6IEe+JtJiO+8cT 9eEgtNnlmQ93FlDx/0vBgfu/yYQuYbYGNf2KkTdCAG5nUX6e2YcbJfrxF4XaPwyr3wlrWvzxTGDs F6XLUYIW03XzzenAzxxgfvzot43kQtpHVQ/OscKpYmzk/VoYVxS1pUeElXVOsD2J9d2P0s7JRWsF HOOOrKwthQH07V/zWpcZnA4XYzLrTc8I3rClBPENQs2OJIfugMZMhnfSfnN/RftagGmu9xMfeE/b cLMlS4gq+AO0vKLAkhUGVsF4RRr8e0GbnkfGZgMEaKECAwEAAaAyMDAGCSqGSIb3DQEJDjEjMCEw DwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAcYwDQYJKoZIhvcNAQELBQADggGBAEovuaqI PqMhouMo1+T0EQnrSf5m49cl9gCcx2C8KOeHvUcdVPo4cF0fjOiBHb61FtnXX1jY6nXWdYpoT6X9 /ibt6khQ1e1Bxuqj1991qHzhO80rxIEOHqmSIZfTXhGi4ng/H+TSJg+ZZ6FcDWmqgIxcqqexsTUY 417ePZiVNDwBVgSWeRubtb3Hf9koR2M3W7mzPfeI9A2XhrXr4vk0SvAxPSacyI5+ky4oLkhmbtpA c5JhWlVh4tWYGQG92cTiiACQ87zf/TUo6GlOPWMO23xWV8uVL2+0Qwx8npgSpNVRzHX3dqvzJu1A qjwOtibKz51/eEl2jIbwHhgoL9AWjKD27UDHNfW3RGOSb7cR7iP4q25qMAKjcI6sgdHKPeMOSY08 rV58TmygSM9Xt44yjZnuCT5SQIg4IhL3N00x2DaTow23sba1QlBS+BJcnowGTTcQba8rxLk6UqYJ oRkEPStQGkCxREXUeNzsCg/JujA6a1HMiiB+8dTvyO86p9g+9Q== -----END CERTIFICATE REQUEST----- FINE: CertRequestRepository: - subject: CN=Certificate Authority,O=REDACTED_DOMAIN.COM FINE: CertRequestRepository: Updating profile for request 0x1 FINE: CertRequestRepository: - profile: caCert.profile FINE: CertRequestRepository: - adjust validity: false FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Adding cn=1,ou=ca, ou=requests,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class request FINE: LDAPRegistry: Adding object class extensibleObject FINE: LDAPRegistry: Mapping attribute requestId FINE: RequestIdMapper: Mapping requestId to requestId FINE: LDAPRegistry: Mapping attribute requestState FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPRegistry: Mapping attribute requestCreateTime FINE: DateMapper: Mapping requestCreateTime to dateOfCreate FINE: LDAPRegistry: Mapping attribute requestModifyTime FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: LDAPRegistry: Skipping empty attribute requestSourceId FINE: LDAPRegistry: Skipping empty attribute requestOwner FINE: LDAPRegistry: Skipping empty attribute realm FINE: LDAPRegistry: Mapping attribute requestExtData FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPRegistry: Mapping attribute requestType FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - objectclass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(DBSubsystem) FINE: LDAPConnThread: Closing output stream FINE: LDAPConnThread: Closing input stream FINE: LDAPConnThread: Closing connection FINE: LdapBoundConnFactory: disconnecting master connection FINE: LDAPConnThread: Closing connection INFO: Creating cert ID for signing cert INFO: - cert ID: 0x1 INFO: Creating signing cert INFO: Importing signing cert DEBUG: - cert: MIIElzCCAv+gAwIBAgIBATANBgkqhkiG9w0BAQsFADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzUyMjdaFw00MjEyMTcyMzUyMjdaMDoxGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEApvkK92tmgf6gzc7YvEOKeMIM2vA4ib/aZYGjNA/rs6KKAKc9ZA3WWi/jmiskXCA6iidKX0EEBtlwYiC/mmRV5CG61/JG7s68OK0SIxHQi0Li2yKrbeGjFlcveJuM0baTGS3bA995lbiqGNfKNl1LoLGTJs7QPA/NAhX6xqTD91W35ueYO8n5G2rAlgyQAGGvBntFeZeH6tA4DrZkHzBgSe/YZkllAN4hJ0QOiBHvibSYjvvHE/XhILTZ5ZkPdxZQ8f9LwYH7v8mELmG2BjX9ipE3QgBuZ1F+ntmHGyX68ReF2j8Mq98Ja1r88Uxg7Bely1GCFtN1883pwM8cYH786LeN5ELaR1UPzrHCqWJs5P1aGFcUtaVHhJV1TrA9ifXdj9LOyUVrBRzjjqysLYUB9O1f81qXGZwOF2My603PCN6wpQTxDULNjiSH7oDGTIZ30n5zf0X7WoBprvcTH3hP23CzJUuIKvgDtLyiwJIVBlbBeEUa/HtBm55HxmYDBGihAgMBAAGjgacwgaQwHwYDVR0jBBgwFoAUnCHM6adwr08G/ZX+WF9+wfZnocYwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAcYwHQYDVR0OBBYEFJwhzOmncK9PBv2V/lhffsH2Z6HGMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL2lwYS1jYS5tb25pdmFncm91cC5jb20vY2Evb2NzcDANBgkqhkiG9w0BAQsFAAOCAYEAmk/NzYQfLywaP+vwIQxW7csqgWymAanHwHEwQa4nGs3be80jYPyr9u8x2yStxX93o5U3IwHyzMprSN5VehUT4RuFwzMaAscI3cjTtn0IL0GTEjeTMtUYvhj6bNg58tS1RRYDqUcI4Ug5r/KjPxfcTVDh7/XSX1MDgWwbf092Sx7+3OnBwxvkgk4xYthwRVfsPOT4UG5Wiad2q149ZYDWhzf+Kwft5hBoY1ZSvxoNzXjXP5ch25ObVpmw03OYFLWtMDfcsKJim+VvS0EN9TvYPqcLYzkfEfPn4kGwg/1+oz6zT6ODkfAdePqF3FqVD93ZqlX6o6R0jILJ+lLVDhKD9hZ/tJE/1JnBjdIuXzGQgzCayXCpSIkoDYVDtxFHp5p0s5Xm3kcci9bmB9P8XtlVQ25ha2fMl4/cWzI5U9kn7NSrksxBqlwLYf3ffCZ6bkBwBzto6xst4grBqvDy1xusxEafx6+VZAxH5ep/2YvBzDDclc5WvZ447jL6iPS+P9lT DEBUG: Command: /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-import --debug --cert /tmp/tmptj1rrcib/cert.crt --format PEM --request 0x1 --profile caCert.profile INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/caCert.profile FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: Setting internaldb.basedn=o=ipaca FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(true) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: registered: false FINE: CertificateRepository: Initializing certificate repository FINE: CertificateRepository: - base DN: ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - cert ID generator: null FINE: CertificateRepository: - range DN: ou=certificateRepository,ou=ranges,o=ipaca FINE: CertificateRepository: - min serial: 1 FINE: CertificateRepository: - max serial: 268435456 FINE: CertificateRepository: - next min serial: null FINE: CertificateRepository: - next max serial: null INFO: Creating cert record 0x1: INFO: - subject: CN=Certificate Authority,O=REDACTED_DOMAIN.COM INFO: - issuer: CN=Certificate Authority,O=REDACTED_DOMAIN.COM INFO: - request ID: 0x1 INFO: - profile ID mapping: caCACert FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: CertificateRepository: Adding certificate record cn=1,ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - subject: CN=Certificate Authority,O=REDACTED_DOMAIN.COM FINE: CertificateRepository: - issuer: CN=Certificate Authority,O=REDACTED_DOMAIN.COM FINE: CertificateRepository: - issued by: system FINE: CertificateRepository: - status: VALID INFO: LDAPSession: Adding cn=1,ou=certificateRepository, ou=ca,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class certificateRecord FINE: LDAPRegistry: Mapping attribute certRecordId FINE: BigIntegerMapper: Mapping certRecordId to serialno FINE: LDAPRegistry: Mapping attribute certMetaInfo FINE: MetaInfoMapper: Mapping certMetaInfo to metaInfo FINE: LDAPRegistry: Skipping empty attribute certRevoInfo FINE: LDAPRegistry: Mapping attribute x509cert FINE: X509CertImplMapper: Mapping x509cert to notBefore FINE: X509CertImplMapper: Mapping x509cert to notAfter FINE: X509CertImplMapper: Mapping x509cert to duration FINE: X509CertImplMapper: Mapping x509cert to subjectName FINE: X509CertImplMapper: Mapping x509cert to issuerName FINE: X509CertImplMapper: Mapping x509cert to publicKeyData FINE: X509CertImplMapper: Mapping x509cert to extension FINE: X509CertImplMapper: Mapping x509cert to userCertificate;binary FINE: X509CertImplMapper: Mapping x509cert to version FINE: X509CertImplMapper: Mapping x509cert to algorithmId FINE: X509CertImplMapper: Mapping x509cert to signingAlgorithmId FINE: LDAPRegistry: Mapping attribute certCreateTime FINE: DateMapper: Mapping certCreateTime to dateOfCreate FINE: LDAPRegistry: Mapping attribute certModifyTime FINE: DateMapper: Mapping certModifyTime to dateOfModify FINE: LDAPRegistry: Mapping attribute certStatus FINE: StringMapper: Mapping certStatus to certStatus FINE: LDAPRegistry: Mapping attribute certAutoRenew FINE: StringMapper: Mapping certAutoRenew to autoRenew FINE: LDAPRegistry: Mapping attribute certIssuedBy FINE: StringMapper: Mapping certIssuedBy to issuedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedOn FINE: LDAPSession: - objectclass FINE: LDAPSession: - serialno FINE: LDAPSession: - metaInfo FINE: LDAPSession: - notBefore FINE: LDAPSession: - notAfter FINE: LDAPSession: - duration FINE: LDAPSession: - subjectName FINE: LDAPSession: - issuerName FINE: LDAPSession: - publicKeyData FINE: LDAPSession: - extension FINE: LDAPSession: - userCertificate;binary FINE: LDAPSession: - version FINE: LDAPSession: - algorithmId FINE: LDAPSession: - signingAlgorithmId FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - certStatus FINE: LDAPSession: - autoRenew FINE: LDAPSession: - issuedBy FINE: LdapBoundConnFactory: number of connections: 1 INFO: Updating request record 0x1 FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: null FINE: RequestRepository: - range DN: ou=requests,ou=ranges,o=ipaca FINE: RequestRepository: - min serial: 1 FINE: RequestRepository: - max serial: 10000000 FINE: RequestRepository: - next min serial: null FINE: RequestRepository: - next max serial: null FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Retrieving cn=1,ou=ca, ou=requests,o=ipaca FINE: LDAPSession: - objectClass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LDAPSession: - cn FINE: LdapBoundConnFactory: number of connections: 1 FINE: CertRequestRepository: Updating cert for request 0x1 FINE: CertRequestRepository: - cert serial number: 0x1 FINE: RequestRecord.loadExtDataFromRequest: missing subject name. Processing extracting subjectName from req_x509info FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Modifying cn=1,ou=ca, ou=requests,o=ipaca FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPSession: - replace: requestState FINE: StringMapper: Mapping requestSourceId to requestSourceId FINE: LDAPSession: - replace: requestSourceId FINE: StringMapper: Mapping requestOwner to requestOwner FINE: LDAPSession: - replace: requestOwner FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: LDAPSession: - replace: dateOfModify FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fissued--005fcert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fx509info FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPSession: - replace: extdata-req--005fissued--005fcert FINE: LDAPSession: - replace: extdata-profileapprovedby FINE: LDAPSession: - replace: extdata-origprofileid FINE: LDAPSession: - replace: extdata-cert--005frequest FINE: LDAPSession: - replace: extdata-profile FINE: LDAPSession: - replace: extdata-cert--005frequest--005ftype FINE: LDAPSession: - replace: extdata-requestversion FINE: LDAPSession: - replace: extdata-dbstatus FINE: LDAPSession: - replace: extdata-subject FINE: LDAPSession: - replace: extdata-requeststatus FINE: LDAPSession: - replace: extdata-isencryptioncert FINE: LDAPSession: - replace: extdata-req--005fkey FINE: LDAPSession: - replace: extdata-profileid FINE: LDAPSession: - replace: extdata-requestid FINE: LDAPSession: - replace: extdata-req--005fx509info FINE: LDAPSession: - replace: extdata-req--005fseq--005fnum FINE: LDAPSession: - replace: extdata-profilesetid FINE: LDAPSession: - replace: extdata-requesttype FINE: LDAPSession: - replace: extdata-req--005fextensions FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - replace: requestType FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(DBSubsystem) FINE: LDAPConnThread: Closing output stream FINE: LDAPConnThread: Closing input stream FINE: LDAPConnThread: Closing connection FINE: LdapBoundConnFactory: disconnecting master connection FINE: LDAPConnThread: Closing connection INFO: - serial: 0x1 INFO: Storing cert and request for signing INFO: Importing signing cert into NSS database DEBUG: NSSDatabase.add_cert(caSigningCert cert-pki-ca) DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpa2iyzx3x/password.txt nss-cert-import --format PEM --debug caSigningCert cert-pki-ca INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Storing password into /tmp/nss-password-6314004146291551596.txt FINE: NSSDatabase: Command: certutil -A -d /etc/pki/pki-tomcat/alias -f /tmp/nss-password-6314004146291551596.txt -a -n "caSigningCert cert-pki-ca" -t ,, -i /tmp/nss-cert-17750070360068435265.crt INFO: Initializing CA INFO: Setting up ocsp_signing cert DEBUG: PKISubsystem.get_subsystem_cert(ocsp_signing) INFO: Getting ocsp_signing cert info from CS.cfg DEBUG: PKISubsystem.get_nssdb_cert_info(ocsp_signing) INFO: Getting ocsp_signing cert info from NSS database DEBUG: NSSDatabase.get_cert_info(ocspSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(ocspSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmp0lcqo5j2/password.txt -n ocspSigningCert cert-pki-ca -a DEBUG: Cert not found: ocspSigningCert cert-pki-ca DEBUG: PKIDeployer.setup_system_cert() DEBUG: NSSDatabase.get_cert_info(ocspSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(ocspSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmpqjt43nn8/password.txt -n ocspSigningCert cert-pki-ca -a DEBUG: Cert not found: ocspSigningCert cert-pki-ca INFO: ocsp_signing cert does not exist in NSS database INFO: Creating ocsp_signing key DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmp2o8ckr9l/password.txt nss-key-create --output-format json --key-type RSA --key-size 2048 --debug INFO: - key ID: 0x916e4d1df723341bb483fb9346123cec57bcf621 INFO: Creating ocsp_signing cert request DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpa2iyzx3x/password.txt nss-cert-request --subject cn=OCSP Subsystem,O=REDACTED_DOMAIN.COM --csr /tmp/tmp75b3k6d4/request.csr --key-id 0x916e4d1df723341bb483fb9346123cec57bcf621 --hash SHA256 --debug INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Loading key 0x916e4d1df723341bb483fb9346123cec57bcf621 FINE: NSSDatabase: - class: org.mozilla.jss.pkcs11.PK11RSAPrivateKey FINE: NSSDatabase: - algorithm: RSA FINE: NSSDatabase: - format: null FINE: NSSDatabase: - key type: RSA FINE: NSSDatabase: - size: 2048 FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: cn=OCSP Subsystem,O=REDACTED_DOMAIN.COM FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: cn=OCSP Subsystem,O=REDACTED_DOMAIN.COM FINE: CryptoUtil: - attributes: DEBUG: - request: MIICeDCCAWACAQAwMzEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMRcwFQYDVQQDDA5PQ1NQIFN1YnN5c3RlbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAOB+OvA1PcrL6czvWeh0LgUiJrs8KBoEOFLcR8DVRH2XL3OlH4JntSSLIz12i49JUWktXEG4kIWaJiQqAaE16/k4z4O63LBoCGKg0FNRXX4+7Kzs0y8SllRqMkpVmAFved6ZMCgrS8lzmAlWDKzYHLrrUJTXoDmZwG8gZoPy4iSd1OZaPzKjAr1N6wqiVHFWFH1fdXK2e9QxhrRFHKGKqvrJP6Alw6fJYKbo00cwwO5cWhXYDj8uMj/DfSiZux+J1/Awdm211krfDBH4pdZQdBhRiXQU/SDKQFxl8Wq1ADycjdj4W0TCXN9sLzjPv2oybeYJMtirnw1dZ1BpmOKZVAECAwEAAaAAMA0GCSqGSIb3DQEBCwUAA4IBAQAt4kHmlF/7cF8FjID6bPoXPbf/lq+4YONRhRCSzaZD3txZ0PAbsIxGZUFILlkGT3v1wgFXJbIeQTaFWoU/kdHQe4v2fRGSz/J3fxVaxmuhDDolWx8dBcM118S3rP6xUJNbqZP8ybUHwlFip1UdKFKSDqImNEG1J5UCp1LpecQk8shXLRUYUg8elwBbBknEE89J1ORkupHw34uobfERaYnkh+jjpdqI3WIU3grQis4/MbeS1sKuZRwarJ16TsSiUmOPtH0Nj2kUSDeFlpbb9j75+e4dWyVai7SHbxf1e+Wa6xSS2hfez/0hKfTQENLFcU2FlzrOyiBd2VxUibneJpIn INFO: Creating request ID for ocsp_signing cert INFO: - request ID: 0x2 INFO: Importing request for ocsp_signing cert DEBUG: Command: /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-request-import --debug --csr /tmp/tmp4jz4h8e_/cert.csr --type pkcs10 --profile caOCSPCert.profile --adjust-validity --output-format json 0x2 INFO: Importing /tmp/tmp4jz4h8e_/cert.csr INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/caOCSPCert.profile FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: Setting internaldb.basedn=o=ipaca FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(true) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: registered: false FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: null FINE: RequestRepository: - range DN: ou=requests,ou=ranges,o=ipaca FINE: RequestRepository: - min serial: 1 FINE: RequestRepository: - max serial: 10000000 FINE: RequestRepository: - next min serial: null FINE: RequestRepository: - next max serial: null FINE: CertRequestRepository: Creating request 0x2 FINE: CertRequestRepository: Updating request 0x2 FINE: CertRequestRepository: - type: pkcs10 FINE: CertRequestRepository: - request: -----BEGIN CERTIFICATE REQUEST----- MIICeDCCAWACAQAwMzEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMRcwFQYDVQQDDA5PQ1NQIFN1 YnN5c3RlbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAOB+OvA1PcrL6czvWeh0LgUi Jrs8KBoEOFLcR8DVRH2XL3OlH4JntSSLIz12i49JUWktXEG4kIWaJiQqAaE16/k4z4O63LBoCGKg 0FNRXX4+7Kzs0y8SllRqMkpVmAFved6ZMCgrS8lzmAlWDKzYHLrrUJTXoDmZwG8gZoPy4iSd1OZa PzKjAr1N6wqiVHFWFH1fdXK2e9QxhrRFHKGKqvrJP6Alw6fJYKbo00cwwO5cWhXYDj8uMj/DfSiZ ux+J1/Awdm211krfDBH4pdZQdBhRiXQU/SDKQFxl8Wq1ADycjdj4W0TCXN9sLzjPv2oybeYJMtir nw1dZ1BpmOKZVAECAwEAAaAAMA0GCSqGSIb3DQEBCwUAA4IBAQAt4kHmlF/7cF8FjID6bPoXPbf/ lq+4YONRhRCSzaZD3txZ0PAbsIxGZUFILlkGT3v1wgFXJbIeQTaFWoU/kdHQe4v2fRGSz/J3fxVa xmuhDDolWx8dBcM118S3rP6xUJNbqZP8ybUHwlFip1UdKFKSDqImNEG1J5UCp1LpecQk8shXLRUY Ug8elwBbBknEE89J1ORkupHw34uobfERaYnkh+jjpdqI3WIU3grQis4/MbeS1sKuZRwarJ16TsSi UmOPtH0Nj2kUSDeFlpbb9j75+e4dWyVai7SHbxf1e+Wa6xSS2hfez/0hKfTQENLFcU2FlzrOyiBd 2VxUibneJpIn -----END CERTIFICATE REQUEST----- FINE: CertRequestRepository: - subject: CN=OCSP Subsystem,O=REDACTED_DOMAIN.COM FINE: CertRequestRepository: Updating profile for request 0x2 FINE: CertRequestRepository: - profile: caOCSPCert.profile FINE: CertRequestRepository: - adjust validity: false FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Adding cn=2,ou=ca, ou=requests,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class request FINE: LDAPRegistry: Adding object class extensibleObject FINE: LDAPRegistry: Mapping attribute requestId FINE: RequestIdMapper: Mapping requestId to requestId FINE: LDAPRegistry: Mapping attribute requestState FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPRegistry: Mapping attribute requestCreateTime FINE: DateMapper: Mapping requestCreateTime to dateOfCreate FINE: LDAPRegistry: Mapping attribute requestModifyTime FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: LDAPRegistry: Skipping empty attribute requestSourceId FINE: LDAPRegistry: Skipping empty attribute requestOwner FINE: LDAPRegistry: Skipping empty attribute realm FINE: LDAPRegistry: Mapping attribute requestExtData FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPRegistry: Mapping attribute requestType FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - objectclass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(DBSubsystem) FINE: LDAPConnThread: Closing output stream FINE: LDAPConnThread: Closing connection FINE: LdapBoundConnFactory: disconnecting master connection FINE: LDAPConnThread: Closing connection INFO: Creating cert ID for ocsp_signing cert INFO: - cert ID: 0x2 INFO: Creating ocsp_signing cert INFO: Importing ocsp_signing cert DEBUG: - cert: MIID9jCCAl6gAwIBAgIBAjANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzUyMzVaFw0yNDEyMDYyMzUyMzVaMDMxGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEXMBUGA1UEAwwOT0NTUCBTdWJzeXN0ZW0wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDgfjrwNT3Ky+nM71nodC4FIia7PCgaBDhS3EfA1UR9ly9zpR+CZ7UkiyM9douPSVFpLVxBuJCFmiYkKgGhNev5OM+DutywaAhioNBTUV1+Puys7NMvEpZUajJKVZgBb3nemTAoK0vJc5gJVgys2By661CU16A5mcBvIGaD8uIkndTmWj8yowK9TesKolRxVhR9X3VytnvUMYa0RRyhiqr6yT+gJcOnyWCm6NNHMMDuXFoV2A4/LjI/w30ombsfidfwMHZttdZK3wwR+KXWUHQYUYl0FP0gykBcZfFqtQA8nI3Y+FtEwlzfbC84z79qMm3mCTLYq58NXWdQaZjimVQBAgMBAAGjgY0wgYowHwYDVR0jBBgwFoAUnCHM6adwr08G/ZX+WF9+wfZnocYwQQYIKwYBBQUHAQEENTAzMDEGCCsGAQUFBzABhiVodHRwOi8vaXBhLWNhLm1vbml2YWdyb3VwLmNvbS9jYS9vY3NwMBMGA1UdJQQMMAoGCCsGAQUFBwMJMA8GCSsGAQUFBzABBQQCBQAwDQYJKoZIhvcNAQENBQADggGBAKQlYcKWtMgypf3IJHfoe7GRAShtydwp5FAosCEk+kU5TUuIek/fiIGkyVYRWdxzP3aQDHERr/dVHKsMAvSSMwMnpzks3cFj7SwWw5sg+17DPyl6/sH0M4DY4Zaqo6p9PiKAAs+g09ltPiynftGiVw2g4F8CzE7FR7og6yfgZA57eru8nmoMAPQTBYRZrQB0O11eGy6jUvcXWF5Qeh9U/rMkH2hBckijwwqpvVk2ka46p3gvwyIo0ZdxqpvhaxvJ2014LpTqDf+kJBE4g3mW3eM5B+C9Gd1LibVvP8gD2PWY3wWp/sMQ6cxeZN2CAbuexqkTGTrxMDH3sm1BYtPLfh956PPIcCbOLBHxbjLzcGwJbguZIJNcofa8m+OJwJZ2WNDOUHZLBJK42MmVgtKarEEnyu+Hz3npcKY2enfKuujn+mRWgK53NkfN0E+9Bggh19QOR719exfyeMj5C49p00N+fHRgzCEPvjRJeIQ4AZJ6Wqy7c5IJeyZ9f/ubv/+aUg== DEBUG: Command: /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-import --debug --cert /tmp/tmpjfo753ax/cert.crt --format PEM --request 0x2 --profile caOCSPCert.profile INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/caOCSPCert.profile FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: Setting internaldb.basedn=o=ipaca FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(true) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: registered: false FINE: CertificateRepository: Initializing certificate repository FINE: CertificateRepository: - base DN: ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - cert ID generator: null FINE: CertificateRepository: - range DN: ou=certificateRepository,ou=ranges,o=ipaca FINE: CertificateRepository: - min serial: 1 FINE: CertificateRepository: - max serial: 268435456 FINE: CertificateRepository: - next min serial: null FINE: CertificateRepository: - next max serial: null INFO: Creating cert record 0x2: INFO: - subject: CN=OCSP Subsystem,O=REDACTED_DOMAIN.COM INFO: - issuer: CN=Certificate Authority,O=REDACTED_DOMAIN.COM INFO: - request ID: 0x2 INFO: - profile ID mapping: caOCSPCert FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: CertificateRepository: Adding certificate record cn=2,ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - subject: CN=OCSP Subsystem,O=REDACTED_DOMAIN.COM FINE: CertificateRepository: - issuer: CN=Certificate Authority,O=REDACTED_DOMAIN.COM FINE: CertificateRepository: - issued by: system FINE: CertificateRepository: - status: VALID INFO: LDAPSession: Adding cn=2,ou=certificateRepository, ou=ca,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class certificateRecord FINE: LDAPRegistry: Mapping attribute certRecordId FINE: BigIntegerMapper: Mapping certRecordId to serialno FINE: LDAPRegistry: Mapping attribute certMetaInfo FINE: MetaInfoMapper: Mapping certMetaInfo to metaInfo FINE: LDAPRegistry: Skipping empty attribute certRevoInfo FINE: LDAPRegistry: Mapping attribute x509cert FINE: X509CertImplMapper: Mapping x509cert to notBefore FINE: X509CertImplMapper: Mapping x509cert to notAfter FINE: X509CertImplMapper: Mapping x509cert to duration FINE: X509CertImplMapper: Mapping x509cert to subjectName FINE: X509CertImplMapper: Mapping x509cert to issuerName FINE: X509CertImplMapper: Mapping x509cert to publicKeyData FINE: X509CertImplMapper: Mapping x509cert to extension FINE: X509CertImplMapper: Mapping x509cert to userCertificate;binary FINE: X509CertImplMapper: Mapping x509cert to version FINE: X509CertImplMapper: Mapping x509cert to algorithmId FINE: X509CertImplMapper: Mapping x509cert to signingAlgorithmId FINE: LDAPRegistry: Mapping attribute certCreateTime FINE: DateMapper: Mapping certCreateTime to dateOfCreate FINE: LDAPRegistry: Mapping attribute certModifyTime FINE: DateMapper: Mapping certModifyTime to dateOfModify FINE: LDAPRegistry: Mapping attribute certStatus FINE: StringMapper: Mapping certStatus to certStatus FINE: LDAPRegistry: Mapping attribute certAutoRenew FINE: StringMapper: Mapping certAutoRenew to autoRenew FINE: LDAPRegistry: Mapping attribute certIssuedBy FINE: StringMapper: Mapping certIssuedBy to issuedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedOn FINE: LDAPSession: - objectclass FINE: LDAPSession: - serialno FINE: LDAPSession: - metaInfo FINE: LDAPSession: - notBefore FINE: LDAPSession: - notAfter FINE: LDAPSession: - duration FINE: LDAPSession: - subjectName FINE: LDAPSession: - issuerName FINE: LDAPSession: - publicKeyData FINE: LDAPSession: - extension FINE: LDAPSession: - userCertificate;binary FINE: LDAPSession: - version FINE: LDAPSession: - algorithmId FINE: LDAPSession: - signingAlgorithmId FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - certStatus FINE: LDAPSession: - autoRenew FINE: LDAPSession: - issuedBy FINE: LdapBoundConnFactory: number of connections: 1 INFO: Updating request record 0x2 FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: null FINE: RequestRepository: - range DN: ou=requests,ou=ranges,o=ipaca FINE: RequestRepository: - min serial: 1 FINE: RequestRepository: - max serial: 10000000 FINE: RequestRepository: - next min serial: null FINE: RequestRepository: - next max serial: null FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Retrieving cn=2,ou=ca, ou=requests,o=ipaca FINE: LDAPSession: - objectClass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LDAPSession: - cn FINE: LdapBoundConnFactory: number of connections: 1 FINE: CertRequestRepository: Updating cert for request 0x2 FINE: CertRequestRepository: - cert serial number: 0x2 FINE: RequestRecord.loadExtDataFromRequest: missing subject name. Processing extracting subjectName from req_x509info FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Modifying cn=2,ou=ca, ou=requests,o=ipaca FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPSession: - replace: requestState FINE: StringMapper: Mapping requestSourceId to requestSourceId FINE: LDAPSession: - replace: requestSourceId FINE: StringMapper: Mapping requestOwner to requestOwner FINE: LDAPSession: - replace: requestOwner FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: LDAPSession: - replace: dateOfModify FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fissued--005fcert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fx509info FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPSession: - replace: extdata-req--005fissued--005fcert FINE: LDAPSession: - replace: extdata-profileapprovedby FINE: LDAPSession: - replace: extdata-origprofileid FINE: LDAPSession: - replace: extdata-cert--005frequest FINE: LDAPSession: - replace: extdata-profile FINE: LDAPSession: - replace: extdata-cert--005frequest--005ftype FINE: LDAPSession: - replace: extdata-requestversion FINE: LDAPSession: - replace: extdata-dbstatus FINE: LDAPSession: - replace: extdata-subject FINE: LDAPSession: - replace: extdata-requeststatus FINE: LDAPSession: - replace: extdata-isencryptioncert FINE: LDAPSession: - replace: extdata-req--005fkey FINE: LDAPSession: - replace: extdata-profileid FINE: LDAPSession: - replace: extdata-requestid FINE: LDAPSession: - replace: extdata-req--005fx509info FINE: LDAPSession: - replace: extdata-req--005fseq--005fnum FINE: LDAPSession: - replace: extdata-profilesetid FINE: LDAPSession: - replace: extdata-requesttype FINE: LDAPSession: - replace: extdata-req--005fextensions FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - replace: requestType FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(DBSubsystem) FINE: LDAPConnThread: Closing output stream FINE: LDAPConnThread: Closing input stream FINE: LDAPConnThread: Closing connection FINE: LdapBoundConnFactory: disconnecting master connection FINE: LDAPConnThread: Closing connection INFO: - serial: 0x2 INFO: Storing cert and request for ocsp_signing INFO: Importing ocsp_signing cert into NSS database DEBUG: NSSDatabase.add_cert(ocspSigningCert cert-pki-ca) DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpa2iyzx3x/password.txt nss-cert-import --format PEM --debug ocspSigningCert cert-pki-ca INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Storing password into /tmp/nss-password-1262605153056221648.txt FINE: NSSDatabase: Command: certutil -A -d /etc/pki/pki-tomcat/alias -f /tmp/nss-password-1262605153056221648.txt -a -n "ocspSigningCert cert-pki-ca" -t ,, -i /tmp/nss-cert-17515068161626575484.crt INFO: Setting up sslserver cert DEBUG: PKISubsystem.get_subsystem_cert(sslserver) INFO: Getting sslserver cert info from CS.cfg DEBUG: PKISubsystem.get_nssdb_cert_info(sslserver) INFO: Getting sslserver cert info from NSS database DEBUG: NSSDatabase.get_cert_info(Server-Cert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(Server-Cert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmpq_4giebq/password.txt -n Server-Cert cert-pki-ca -a DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(Server-Cert cert-pki-ca) ends DEBUG: NSSDatabase.get_trust(Server-Cert cert-pki-ca) DEBUG: fullname: Server-Cert cert-pki-ca DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmpduc5pec0/password.txt DEBUG: NSSDatabase.get_cert_info(Server-Cert cert-pki-ca) ends DEBUG: PKIDeployer.setup_system_cert() DEBUG: NSSDatabase.get_cert_info(Server-Cert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(Server-Cert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmp9nb6d5kb/password.txt -n Server-Cert cert-pki-ca -a DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(Server-Cert cert-pki-ca) ends DEBUG: NSSDatabase.get_trust(Server-Cert cert-pki-ca) DEBUG: fullname: Server-Cert cert-pki-ca DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmplk5yhrlc/password.txt DEBUG: NSSDatabase.get_cert_info(Server-Cert cert-pki-ca) ends INFO: sslserver cert already exists in NSS database INFO: - serial: 0xf323706fc430ecb91700a2b1fddc6f86 INFO: - subject: CN=master.redacted_domain.com,O=2022-12-18 00:51:31 INFO: - issuer: CN=master.redacted_domain.com,O=2022-12-18 00:51:31 INFO: - trust flags: u,u,u INFO: Searching for sslserver key DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpuz0_ph8w/password.txt nss-key-find --output-format json --nickname Server-Cert cert-pki-ca --debug INFO: - key ID: 0xa83a65115903d30fc2f4ba80b4d4477499fc3d76 INFO: Creating sslserver cert request DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpa2iyzx3x/password.txt nss-cert-request --subject cn=master.redacted_domain.com,O=REDACTED_DOMAIN.COM --csr /tmp/tmpwlpkj2w2/request.csr --key-id 0xa83a65115903d30fc2f4ba80b4d4477499fc3d76 --hash SHA256 --debug INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Loading key 0xa83a65115903d30fc2f4ba80b4d4477499fc3d76 FINE: NSSDatabase: - class: org.mozilla.jss.pkcs11.PK11RSAPrivateKey FINE: NSSDatabase: - algorithm: RSA FINE: NSSDatabase: - format: null FINE: NSSDatabase: - key type: RSA FINE: NSSDatabase: - size: 2048 FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: cn=master.redacted_domain.com,O=REDACTED_DOMAIN.COM FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: cn=master.redacted_domain.com,O=REDACTED_DOMAIN.COM FINE: CryptoUtil: - attributes: DEBUG: - request: MIICgjCCAWoCAQAwPTEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMSEwHwYDVQQDDBhtaWRtMDAxcC5tb25pdmFncm91cC5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDJcNO3VjoFvtNwU/wJpQQN7CAeb5g4eAkGlWo9sRJLHOxuSGhetkhpTNlWqGYoTkc9e/kNH2UnjusqQzSIiOx+8J3aTTZXI8KDpHiEYRLo3iYWzRaNIrVr82RDUHRVn49ZqAvMj5pIOQ7EFr1njsiifvcmmKBI955WAXRy97G+z0TTdTrUDfTqJpHdE8YiMKQiZCq6cxdtvMbF/zzmsetv2HNfz0magYPcXuqiEgOtqZQE5528wFDupiiFxHlApam/ucjQwGpA7Mp0WOOhczMa35TAFrpwlw6VrR7XeuyDOzZvghryd9oc4NUdAgk4dIi7OngAQxGc7Ayn+jy6MJU3AgMBAAGgADANBgkqhkiG9w0BAQsFAAOCAQEAoRSRZCgelnk51C1B+2ZC+II7MOvOg4XTkcceLUHV+bTEvIpEOgC76yPTJxL9+n8objzAVkESOAuYNNK1wada2dGsWMwr4/4RHKilEsFWOfxLOlTDuh889JO89Eh3aeNBvLZSZXFz+7uhyrop8EkyEbQY9DEmLB4dtSJgElfAIeD/KZbBgOnRlQtEnz19HTQWU8Sjz5KC8uuoh2SdpWormKISkjsq7xIFV5QVMMZ7JSIiOMB7ScZiJAoA48I7PPzMmawzUPbozW1WAJtJhxmQUe7WtBWSJPtZXEBFsTflxl/FoNvY5sTBuWawDBwtZ6O1PTLcBg9cJ95lWbFfOqJmDQ== INFO: Creating request ID for sslserver cert INFO: - request ID: 0x3 INFO: Importing request for sslserver cert DEBUG: Command: /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-request-import --debug --csr /tmp/tmp2zwzchoe/cert.csr --type pkcs10 --profile serverCert.profile --adjust-validity --output-format json 0x3 INFO: Importing /tmp/tmp2zwzchoe/cert.csr INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/serverCert.profile FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: Setting internaldb.basedn=o=ipaca FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(true) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: registered: false FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: null FINE: RequestRepository: - range DN: ou=requests,ou=ranges,o=ipaca FINE: RequestRepository: - min serial: 1 FINE: RequestRepository: - max serial: 10000000 FINE: RequestRepository: - next min serial: null FINE: RequestRepository: - next max serial: null FINE: CertRequestRepository: Creating request 0x3 FINE: CertRequestRepository: Updating request 0x3 FINE: CertRequestRepository: - type: pkcs10 FINE: CertRequestRepository: - request: -----BEGIN CERTIFICATE REQUEST----- MIICgjCCAWoCAQAwPTEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMSEwHwYDVQQDDBhtaWRtMDAx cC5tb25pdmFncm91cC5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDJcNO3VjoF vtNwU/wJpQQN7CAeb5g4eAkGlWo9sRJLHOxuSGhetkhpTNlWqGYoTkc9e/kNH2UnjusqQzSIiOx+ 8J3aTTZXI8KDpHiEYRLo3iYWzRaNIrVr82RDUHRVn49ZqAvMj5pIOQ7EFr1njsiifvcmmKBI955W AXRy97G+z0TTdTrUDfTqJpHdE8YiMKQiZCq6cxdtvMbF/zzmsetv2HNfz0magYPcXuqiEgOtqZQE 5528wFDupiiFxHlApam/ucjQwGpA7Mp0WOOhczMa35TAFrpwlw6VrR7XeuyDOzZvghryd9oc4NUd Agk4dIi7OngAQxGc7Ayn+jy6MJU3AgMBAAGgADANBgkqhkiG9w0BAQsFAAOCAQEAoRSRZCgelnk5 1C1B+2ZC+II7MOvOg4XTkcceLUHV+bTEvIpEOgC76yPTJxL9+n8objzAVkESOAuYNNK1wada2dGs WMwr4/4RHKilEsFWOfxLOlTDuh889JO89Eh3aeNBvLZSZXFz+7uhyrop8EkyEbQY9DEmLB4dtSJg ElfAIeD/KZbBgOnRlQtEnz19HTQWU8Sjz5KC8uuoh2SdpWormKISkjsq7xIFV5QVMMZ7JSIiOMB7 ScZiJAoA48I7PPzMmawzUPbozW1WAJtJhxmQUe7WtBWSJPtZXEBFsTflxl/FoNvY5sTBuWawDBwt Z6O1PTLcBg9cJ95lWbFfOqJmDQ== -----END CERTIFICATE REQUEST----- FINE: CertRequestRepository: - subject: CN=master.redacted_domain.com,O=REDACTED_DOMAIN.COM FINE: CertRequestRepository: Updating profile for request 0x3 FINE: CertRequestRepository: - profile: serverCert.profile FINE: CertRequestRepository: - adjust validity: false FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Adding cn=3,ou=ca, ou=requests,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class request FINE: LDAPRegistry: Adding object class extensibleObject FINE: LDAPRegistry: Mapping attribute requestId FINE: RequestIdMapper: Mapping requestId to requestId FINE: LDAPRegistry: Mapping attribute requestState FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPRegistry: Mapping attribute requestCreateTime FINE: DateMapper: Mapping requestCreateTime to dateOfCreate FINE: LDAPRegistry: Mapping attribute requestModifyTime FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: LDAPRegistry: Skipping empty attribute requestSourceId FINE: LDAPRegistry: Skipping empty attribute requestOwner FINE: LDAPRegistry: Skipping empty attribute realm FINE: LDAPRegistry: Mapping attribute requestExtData FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPRegistry: Mapping attribute requestType FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - objectclass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(DBSubsystem) FINE: LDAPConnThread: Closing output stream FINE: LDAPConnThread: Closing connection FINE: LdapBoundConnFactory: disconnecting master connection FINE: LDAPConnThread: Closing connection INFO: Creating cert ID for sslserver cert INFO: - cert ID: 0x3 INFO: Creating sslserver cert INFO: Importing sslserver cert DEBUG: - cert: MIIEJDCCAoygAwIBAgIBAzANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzUyNDFaFw0yNDEyMDYyMzUyNDFaMD0xGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEhMB8GA1UEAwwYbWlkbTAwMXAubW9uaXZhZ3JvdXAuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyXDTt1Y6Bb7TcFP8CaUEDewgHm+YOHgJBpVqPbESSxzsbkhoXrZIaUzZVqhmKE5HPXv5DR9lJ47rKkM0iIjsfvCd2k02VyPCg6R4hGES6N4mFs0WjSK1a/NkQ1B0VZ+PWagLzI+aSDkOxBa9Z47Ion73JpigSPeeVgF0cvexvs9E03U61A306iaR3RPGIjCkImQqunMXbbzGxf885rHrb9hzX89JmoGD3F7qohIDramUBOedvMBQ7qYohcR5QKWpv7nI0MBqQOzKdFjjoXMzGt+UwBa6cJcOla0e13rsgzs2b4Ia8nfaHODVHQIJOHSIuzp4AEMRnOwMp/o8ujCVNwIDAQABo4GxMIGuMB8GA1UdIwQYMBaAFJwhzOmncK9PBv2V/lhffsH2Z6HGMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL2lwYS1jYS5tb25pdmFncm91cC5jb20vY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBLAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwIwYDVR0RBBwwGoIYbWlkbTAwMXAubW9uaXZhZ3JvdXAuY29tMA0GCSqGSIb3DQEBDQUAA4IBgQAeRUPXDCTkZD3nvA8/sG4ZA0TKhvIvXiVJzWlgu7HIhLwuslSsRo9zb4O7eXkMB932Ih/mCpdxW9dCYJLeSWXTRJufsZi6XwaCsiWhZknH40zP5pe0KZMGB9JsHaQru8Kmo/mFhmJd+45V1lArIAlaNEdLBrC/5RPm1E5DC6xhBjbjEbfgO7LZ5+qETfG1f0Dgpz3Nc1JPJxU99F6MxFWdotYpB36QEbo9s7mt0ps5jYQVHYxjTFzVTDCviHoQRv91iWwOefz57bVJs+0+mrDWX271YyMp2D4LLbnMmGIhIqBYEWmc3PH24SK3sHdGCpV33Woc/co/i9mE7ZGD8PJLcd9UDGYhIEvDZ0RA8sr5KW0wSITsfxK/BqQPYqDRXtuRfKKzfll3stzBYVJExjnJm3cKxEmXVp024eL9CYlBzNfn6Rv0JSptTjki181KXf+7wpsxX/a1qeBfK9QxqAOHXfD63jSdu3b+azIvscYM9BAmb4b4if2llhC/Zk+0KG0= DEBUG: Command: /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-import --debug --cert /tmp/tmp4jhqmxhb/cert.crt --format PEM --request 0x3 --profile serverCert.profile INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/serverCert.profile FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: Setting internaldb.basedn=o=ipaca FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(true) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: registered: false FINE: CertificateRepository: Initializing certificate repository FINE: CertificateRepository: - base DN: ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - cert ID generator: null FINE: CertificateRepository: - range DN: ou=certificateRepository,ou=ranges,o=ipaca FINE: CertificateRepository: - min serial: 1 FINE: CertificateRepository: - max serial: 268435456 FINE: CertificateRepository: - next min serial: null FINE: CertificateRepository: - next max serial: null INFO: Creating cert record 0x3: INFO: - subject: CN=master.redacted_domain.com,O=REDACTED_DOMAIN.COM INFO: - issuer: CN=Certificate Authority,O=REDACTED_DOMAIN.COM INFO: - request ID: 0x3 INFO: - profile ID mapping: caServerCert FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: CertificateRepository: Adding certificate record cn=3,ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - subject: CN=master.redacted_domain.com,O=REDACTED_DOMAIN.COM FINE: CertificateRepository: - issuer: CN=Certificate Authority,O=REDACTED_DOMAIN.COM FINE: CertificateRepository: - issued by: system FINE: CertificateRepository: - status: VALID INFO: LDAPSession: Adding cn=3,ou=certificateRepository, ou=ca,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class certificateRecord FINE: LDAPRegistry: Mapping attribute certRecordId FINE: BigIntegerMapper: Mapping certRecordId to serialno FINE: LDAPRegistry: Mapping attribute certMetaInfo FINE: MetaInfoMapper: Mapping certMetaInfo to metaInfo FINE: LDAPRegistry: Skipping empty attribute certRevoInfo FINE: LDAPRegistry: Mapping attribute x509cert FINE: X509CertImplMapper: Mapping x509cert to notBefore FINE: X509CertImplMapper: Mapping x509cert to notAfter FINE: X509CertImplMapper: Mapping x509cert to duration FINE: X509CertImplMapper: Mapping x509cert to subjectName FINE: X509CertImplMapper: Mapping x509cert to issuerName FINE: X509CertImplMapper: Mapping x509cert to publicKeyData FINE: X509CertImplMapper: Mapping x509cert to extension FINE: X509CertImplMapper: Mapping x509cert to userCertificate;binary FINE: X509CertImplMapper: Mapping x509cert to version FINE: X509CertImplMapper: Mapping x509cert to algorithmId FINE: X509CertImplMapper: Mapping x509cert to signingAlgorithmId FINE: LDAPRegistry: Mapping attribute certCreateTime FINE: DateMapper: Mapping certCreateTime to dateOfCreate FINE: LDAPRegistry: Mapping attribute certModifyTime FINE: DateMapper: Mapping certModifyTime to dateOfModify FINE: LDAPRegistry: Mapping attribute certStatus FINE: StringMapper: Mapping certStatus to certStatus FINE: LDAPRegistry: Mapping attribute certAutoRenew FINE: StringMapper: Mapping certAutoRenew to autoRenew FINE: LDAPRegistry: Mapping attribute certIssuedBy FINE: StringMapper: Mapping certIssuedBy to issuedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedOn FINE: LDAPSession: - objectclass FINE: LDAPSession: - serialno FINE: LDAPSession: - metaInfo FINE: LDAPSession: - notBefore FINE: LDAPSession: - notAfter FINE: LDAPSession: - duration FINE: LDAPSession: - subjectName FINE: LDAPSession: - issuerName FINE: LDAPSession: - publicKeyData FINE: LDAPSession: - extension FINE: LDAPSession: - userCertificate;binary FINE: LDAPSession: - version FINE: LDAPSession: - algorithmId FINE: LDAPSession: - signingAlgorithmId FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - certStatus FINE: LDAPSession: - autoRenew FINE: LDAPSession: - issuedBy FINE: LdapBoundConnFactory: number of connections: 1 INFO: Updating request record 0x3 FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: null FINE: RequestRepository: - range DN: ou=requests,ou=ranges,o=ipaca FINE: RequestRepository: - min serial: 1 FINE: RequestRepository: - max serial: 10000000 FINE: RequestRepository: - next min serial: null FINE: RequestRepository: - next max serial: null FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Retrieving cn=3,ou=ca, ou=requests,o=ipaca FINE: LDAPSession: - objectClass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LDAPSession: - cn FINE: LdapBoundConnFactory: number of connections: 1 FINE: CertRequestRepository: Updating cert for request 0x3 FINE: CertRequestRepository: - cert serial number: 0x3 FINE: RequestRecord.loadExtDataFromRequest: missing subject name. Processing extracting subjectName from req_x509info FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Modifying cn=3,ou=ca, ou=requests,o=ipaca FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPSession: - replace: requestState FINE: StringMapper: Mapping requestSourceId to requestSourceId FINE: LDAPSession: - replace: requestSourceId FINE: StringMapper: Mapping requestOwner to requestOwner FINE: LDAPSession: - replace: requestOwner FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: LDAPSession: - replace: dateOfModify FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fissued--005fcert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fx509info FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPSession: - replace: extdata-req--005fissued--005fcert FINE: LDAPSession: - replace: extdata-profileapprovedby FINE: LDAPSession: - replace: extdata-origprofileid FINE: LDAPSession: - replace: extdata-cert--005frequest FINE: LDAPSession: - replace: extdata-profile FINE: LDAPSession: - replace: extdata-cert--005frequest--005ftype FINE: LDAPSession: - replace: extdata-requestversion FINE: LDAPSession: - replace: extdata-dbstatus FINE: LDAPSession: - replace: extdata-subject FINE: LDAPSession: - replace: extdata-requeststatus FINE: LDAPSession: - replace: extdata-isencryptioncert FINE: LDAPSession: - replace: extdata-req--005fkey FINE: LDAPSession: - replace: extdata-profileid FINE: LDAPSession: - replace: extdata-requestid FINE: LDAPSession: - replace: extdata-req--005fx509info FINE: LDAPSession: - replace: extdata-req--005fseq--005fnum FINE: LDAPSession: - replace: extdata-profilesetid FINE: LDAPSession: - replace: extdata-requesttype FINE: LDAPSession: - replace: extdata-req--005fextensions FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - replace: requestType FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(DBSubsystem) FINE: LDAPConnThread: Closing output stream FINE: LDAPConnThread: Closing input stream FINE: LDAPConnThread: Closing connection FINE: LdapBoundConnFactory: disconnecting master connection FINE: LDAPConnThread: Closing connection INFO: - serial: 0x3 INFO: Storing cert and request for sslserver INFO: Setting up subsystem cert DEBUG: PKISubsystem.get_subsystem_cert(subsystem) INFO: Getting subsystem cert info from CS.cfg DEBUG: PKISubsystem.get_nssdb_cert_info(subsystem) INFO: Getting subsystem cert info from NSS database DEBUG: NSSDatabase.get_cert_info(subsystemCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmpmo_hnz13/password.txt -n subsystemCert cert-pki-ca -a DEBUG: Cert not found: subsystemCert cert-pki-ca DEBUG: PKIDeployer.setup_system_cert() DEBUG: NSSDatabase.get_cert_info(subsystemCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmpirip2cyz/password.txt -n subsystemCert cert-pki-ca -a DEBUG: Cert not found: subsystemCert cert-pki-ca INFO: subsystem cert does not exist in NSS database INFO: Creating subsystem key DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmphuhskvj6/password.txt nss-key-create --output-format json --key-type RSA --key-size 2048 --debug INFO: - key ID: 0xd28f97f6490c1f8dc628d469e35824dac154112f INFO: Creating subsystem cert request DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpa2iyzx3x/password.txt nss-cert-request --subject cn=CA Subsystem,O=REDACTED_DOMAIN.COM --csr /tmp/tmpnxk4nyeh/request.csr --key-id 0xd28f97f6490c1f8dc628d469e35824dac154112f --hash SHA256 --debug INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Loading key 0xd28f97f6490c1f8dc628d469e35824dac154112f FINE: NSSDatabase: - class: org.mozilla.jss.pkcs11.PK11RSAPrivateKey FINE: NSSDatabase: - algorithm: RSA FINE: NSSDatabase: - format: null FINE: NSSDatabase: - key type: RSA FINE: NSSDatabase: - size: 2048 FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: cn=CA Subsystem,O=REDACTED_DOMAIN.COM FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: cn=CA Subsystem,O=REDACTED_DOMAIN.COM FINE: CryptoUtil: - attributes: DEBUG: - request: MIICdjCCAV4CAQAwMTEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMRUwEwYDVQQDDAxDQSBTdWJzeXN0ZW0wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDMOFARC7ciiDYCkmN4jD7cmLzCRdyE+txNuFqZI8A11x2qdSu6tbFVo7Z7Z/6O2nR//iG+B4lp9zSGJMAYND/BQEdEzTSIWuxUjsS5Xuqy+cSbQ700782tgnwhvHjB6Gv79Uo05tpFQsCRLTmd7osvJ6XvYjOYfBfABA1FR8AsHE9JwReHLBxyFepNw58q+ihvCxlCDc+X03tLGPMeoET/1gDs+8Ro/IrWzj1b3W/FHv3fpAIQ4jS5oRVxuLBIRP46BpOi0MuBsBSVnusUUsG3KEsUR/E3sALr0B/yWX9FfD49AVw73qN8JCFFZtFNhRUxV9dUU1QUffPPloPOBrfDAgMBAAGgADANBgkqhkiG9w0BAQsFAAOCAQEAJOXKcxU72geslV0flqFkQVlD2hTaoAIwxvzivBzRnwvBJ0LXSYP+DNJ+FvrNBCBrSiZ5MsGGVOXQtsTxxnbnOyV8DiWesXKhTL5OEu/L9vVBe3xLNOY9KKMwKr/nqZLlzM7vYxg/SUpRciR41Axh9I+jljXTTsjbEgEFcIkubp2yEdugAzLFXo2xq2z0AGepRxebfXag5Ubhc7+AsbnwGXOS3+HYhv9mOBk79flwC0vnaew1+Ts4/BA3zQHy9rJSFSLGk99aY/MASNruRIc11Sp8y1HDHS+U5y5Ad0JSg8SWuNBVqYDdm/XaMyVU1WzCfkLezI/jvgjkMKB+mMj6AA== INFO: Creating request ID for subsystem cert INFO: - request ID: 0x4 INFO: Importing request for subsystem cert DEBUG: Command: /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-request-import --debug --csr /tmp/tmpz6d1t5n7/cert.csr --type pkcs10 --profile subsystemCert.profile --adjust-validity --output-format json 0x4 INFO: Importing /tmp/tmpz6d1t5n7/cert.csr INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/subsystemCert.profile FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: Setting internaldb.basedn=o=ipaca FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(true) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: registered: false FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: null FINE: RequestRepository: - range DN: ou=requests,ou=ranges,o=ipaca FINE: RequestRepository: - min serial: 1 FINE: RequestRepository: - max serial: 10000000 FINE: RequestRepository: - next min serial: null FINE: RequestRepository: - next max serial: null FINE: CertRequestRepository: Creating request 0x4 FINE: CertRequestRepository: Updating request 0x4 FINE: CertRequestRepository: - type: pkcs10 FINE: CertRequestRepository: - request: -----BEGIN CERTIFICATE REQUEST----- MIICdjCCAV4CAQAwMTEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMRUwEwYDVQQDDAxDQSBTdWJz eXN0ZW0wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDMOFARC7ciiDYCkmN4jD7cmLzC RdyE+txNuFqZI8A11x2qdSu6tbFVo7Z7Z/6O2nR//iG+B4lp9zSGJMAYND/BQEdEzTSIWuxUjsS5 Xuqy+cSbQ700782tgnwhvHjB6Gv79Uo05tpFQsCRLTmd7osvJ6XvYjOYfBfABA1FR8AsHE9JwReH LBxyFepNw58q+ihvCxlCDc+X03tLGPMeoET/1gDs+8Ro/IrWzj1b3W/FHv3fpAIQ4jS5oRVxuLBI RP46BpOi0MuBsBSVnusUUsG3KEsUR/E3sALr0B/yWX9FfD49AVw73qN8JCFFZtFNhRUxV9dUU1QU ffPPloPOBrfDAgMBAAGgADANBgkqhkiG9w0BAQsFAAOCAQEAJOXKcxU72geslV0flqFkQVlD2hTa oAIwxvzivBzRnwvBJ0LXSYP+DNJ+FvrNBCBrSiZ5MsGGVOXQtsTxxnbnOyV8DiWesXKhTL5OEu/L 9vVBe3xLNOY9KKMwKr/nqZLlzM7vYxg/SUpRciR41Axh9I+jljXTTsjbEgEFcIkubp2yEdugAzLF Xo2xq2z0AGepRxebfXag5Ubhc7+AsbnwGXOS3+HYhv9mOBk79flwC0vnaew1+Ts4/BA3zQHy9rJS FSLGk99aY/MASNruRIc11Sp8y1HDHS+U5y5Ad0JSg8SWuNBVqYDdm/XaMyVU1WzCfkLezI/jvgjk MKB+mMj6AA== -----END CERTIFICATE REQUEST----- FINE: CertRequestRepository: - subject: CN=CA Subsystem,O=REDACTED_DOMAIN.COM FINE: CertRequestRepository: Updating profile for request 0x4 FINE: CertRequestRepository: - profile: subsystemCert.profile FINE: CertRequestRepository: - adjust validity: false FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Adding cn=4,ou=ca, ou=requests,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class request FINE: LDAPRegistry: Adding object class extensibleObject FINE: LDAPRegistry: Mapping attribute requestId FINE: RequestIdMapper: Mapping requestId to requestId FINE: LDAPRegistry: Mapping attribute requestState FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPRegistry: Mapping attribute requestCreateTime FINE: DateMapper: Mapping requestCreateTime to dateOfCreate FINE: LDAPRegistry: Mapping attribute requestModifyTime FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: LDAPRegistry: Skipping empty attribute requestSourceId FINE: LDAPRegistry: Skipping empty attribute requestOwner FINE: LDAPRegistry: Skipping empty attribute realm FINE: LDAPRegistry: Mapping attribute requestExtData FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPRegistry: Mapping attribute requestType FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - objectclass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(DBSubsystem) FINE: LDAPConnThread: Closing output stream FINE: LDAPConnThread: Closing connection FINE: LdapBoundConnFactory: disconnecting master connection FINE: LDAPConnThread: Closing connection INFO: Creating cert ID for subsystem cert INFO: - cert ID: 0x4 INFO: Creating subsystem cert INFO: Importing subsystem cert DEBUG: - cert: MIID8zCCAlugAwIBAgIBBDANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzUyNDdaFw0yNDEyMDYyMzUyNDdaMDExGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEVMBMGA1UEAwwMQ0EgU3Vic3lzdGVtMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzDhQEQu3Iog2ApJjeIw+3Ji8wkXchPrcTbhamSPANdcdqnUrurWxVaO2e2f+jtp0f/4hvgeJafc0hiTAGDQ/wUBHRM00iFrsVI7EuV7qsvnEm0O9NO/NrYJ8Ibx4wehr+/VKNObaRULAkS05ne6LLyel72IzmHwXwAQNRUfALBxPScEXhywcchXqTcOfKvoobwsZQg3Pl9N7SxjzHqBE/9YA7PvEaPyK1s49W91vxR7936QCEOI0uaEVcbiwSET+OgaTotDLgbAUlZ7rFFLBtyhLFEfxN7AC69Af8ll/RXw+PQFcO96jfCQhRWbRTYUVMVfXVFNUFH3zz5aDzga3wwIDAQABo4GMMIGJMB8GA1UdIwQYMBaAFJwhzOmncK9PBv2V/lhffsH2Z6HGMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL2lwYS1jYS5tb25pdmFncm91cC5jb20vY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBPAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDQYJKoZIhvcNAQENBQADggGBAHRdz+kAMX8554l6bISYdndnZHyVLe2JOOWYsRocpzMOb8nA3m/32/inEMjzlLL9oZ9Z8sKGltkHe51N/U+6Y2Vm6VPHcO2F4rfiX4vF5kLwFbdWrFm1+vzqT9sjDB1uh9pyxJc3I7TNBefhkThveuQ4ut4x+VbFNKt7MVfSl85GBA3qhT1j0oMwwNfwoAvzX4at1sEdhMUmd6zCXKozQfXV2Pn34yCvQIU2RWfu2nE2pcwQJ3f16Xa9yKOnbHGVqQF8lpsohTeLReZ4z8+X7vdVQ7W86G1pFjV51Z072XQpyFRwSHvxGXbG2WF4NZNhc4dR3cJ3CroPK7eeVXX7ZanKM4rwcDsKiW/+kvAp2XQGbHC+DEbU7iuoGIveYEWh53dYzglWpsxtyOGY+KWdrSTiMqKzNV7aSbUzzMsghMb62XDaPxuC2rBqPkHZxvdHfxXJSFnaF1YREWFbygMuMFcVIo3O4uaCIibBNukvJ9Il3NbYS1hUS7mZFXs7pTBhow== DEBUG: Command: /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-import --debug --cert /tmp/tmpjas_zg9s/cert.crt --format PEM --request 0x4 --profile subsystemCert.profile INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/subsystemCert.profile FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: Setting internaldb.basedn=o=ipaca FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(true) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: registered: false FINE: CertificateRepository: Initializing certificate repository FINE: CertificateRepository: - base DN: ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - cert ID generator: null FINE: CertificateRepository: - range DN: ou=certificateRepository,ou=ranges,o=ipaca FINE: CertificateRepository: - min serial: 1 FINE: CertificateRepository: - max serial: 268435456 FINE: CertificateRepository: - next min serial: null FINE: CertificateRepository: - next max serial: null INFO: Creating cert record 0x4: INFO: - subject: CN=CA Subsystem,O=REDACTED_DOMAIN.COM INFO: - issuer: CN=Certificate Authority,O=REDACTED_DOMAIN.COM INFO: - request ID: 0x4 INFO: - profile ID mapping: caSubsystemCert FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: CertificateRepository: Adding certificate record cn=4,ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - subject: CN=CA Subsystem,O=REDACTED_DOMAIN.COM FINE: CertificateRepository: - issuer: CN=Certificate Authority,O=REDACTED_DOMAIN.COM FINE: CertificateRepository: - issued by: system FINE: CertificateRepository: - status: VALID INFO: LDAPSession: Adding cn=4,ou=certificateRepository, ou=ca,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class certificateRecord FINE: LDAPRegistry: Mapping attribute certRecordId FINE: BigIntegerMapper: Mapping certRecordId to serialno FINE: LDAPRegistry: Mapping attribute certMetaInfo FINE: MetaInfoMapper: Mapping certMetaInfo to metaInfo FINE: LDAPRegistry: Skipping empty attribute certRevoInfo FINE: LDAPRegistry: Mapping attribute x509cert FINE: X509CertImplMapper: Mapping x509cert to notBefore FINE: X509CertImplMapper: Mapping x509cert to notAfter FINE: X509CertImplMapper: Mapping x509cert to duration FINE: X509CertImplMapper: Mapping x509cert to subjectName FINE: X509CertImplMapper: Mapping x509cert to issuerName FINE: X509CertImplMapper: Mapping x509cert to publicKeyData FINE: X509CertImplMapper: Mapping x509cert to extension FINE: X509CertImplMapper: Mapping x509cert to userCertificate;binary FINE: X509CertImplMapper: Mapping x509cert to version FINE: X509CertImplMapper: Mapping x509cert to algorithmId FINE: X509CertImplMapper: Mapping x509cert to signingAlgorithmId FINE: LDAPRegistry: Mapping attribute certCreateTime FINE: DateMapper: Mapping certCreateTime to dateOfCreate FINE: LDAPRegistry: Mapping attribute certModifyTime FINE: DateMapper: Mapping certModifyTime to dateOfModify FINE: LDAPRegistry: Mapping attribute certStatus FINE: StringMapper: Mapping certStatus to certStatus FINE: LDAPRegistry: Mapping attribute certAutoRenew FINE: StringMapper: Mapping certAutoRenew to autoRenew FINE: LDAPRegistry: Mapping attribute certIssuedBy FINE: StringMapper: Mapping certIssuedBy to issuedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedOn FINE: LDAPSession: - objectclass FINE: LDAPSession: - serialno FINE: LDAPSession: - metaInfo FINE: LDAPSession: - notBefore FINE: LDAPSession: - notAfter FINE: LDAPSession: - duration FINE: LDAPSession: - subjectName FINE: LDAPSession: - issuerName FINE: LDAPSession: - publicKeyData FINE: LDAPSession: - extension FINE: LDAPSession: - userCertificate;binary FINE: LDAPSession: - version FINE: LDAPSession: - algorithmId FINE: LDAPSession: - signingAlgorithmId FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - certStatus FINE: LDAPSession: - autoRenew FINE: LDAPSession: - issuedBy FINE: LdapBoundConnFactory: number of connections: 1 INFO: Updating request record 0x4 FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: null FINE: RequestRepository: - range DN: ou=requests,ou=ranges,o=ipaca FINE: RequestRepository: - min serial: 1 FINE: RequestRepository: - max serial: 10000000 FINE: RequestRepository: - next min serial: null FINE: RequestRepository: - next max serial: null FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Retrieving cn=4,ou=ca, ou=requests,o=ipaca FINE: LDAPSession: - objectClass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LDAPSession: - cn FINE: LdapBoundConnFactory: number of connections: 1 FINE: CertRequestRepository: Updating cert for request 0x4 FINE: CertRequestRepository: - cert serial number: 0x4 FINE: RequestRecord.loadExtDataFromRequest: missing subject name. Processing extracting subjectName from req_x509info FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Modifying cn=4,ou=ca, ou=requests,o=ipaca FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPSession: - replace: requestState FINE: StringMapper: Mapping requestSourceId to requestSourceId FINE: LDAPSession: - replace: requestSourceId FINE: StringMapper: Mapping requestOwner to requestOwner FINE: LDAPSession: - replace: requestOwner FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: LDAPSession: - replace: dateOfModify FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fissued--005fcert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fx509info FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPSession: - replace: extdata-req--005fissued--005fcert FINE: LDAPSession: - replace: extdata-profileapprovedby FINE: LDAPSession: - replace: extdata-origprofileid FINE: LDAPSession: - replace: extdata-cert--005frequest FINE: LDAPSession: - replace: extdata-profile FINE: LDAPSession: - replace: extdata-cert--005frequest--005ftype FINE: LDAPSession: - replace: extdata-requestversion FINE: LDAPSession: - replace: extdata-dbstatus FINE: LDAPSession: - replace: extdata-subject FINE: LDAPSession: - replace: extdata-requeststatus FINE: LDAPSession: - replace: extdata-isencryptioncert FINE: LDAPSession: - replace: extdata-req--005fkey FINE: LDAPSession: - replace: extdata-profileid FINE: LDAPSession: - replace: extdata-requestid FINE: LDAPSession: - replace: extdata-req--005fx509info FINE: LDAPSession: - replace: extdata-req--005fseq--005fnum FINE: LDAPSession: - replace: extdata-profilesetid FINE: LDAPSession: - replace: extdata-requesttype FINE: LDAPSession: - replace: extdata-req--005fextensions FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - replace: requestType FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(DBSubsystem) FINE: LDAPConnThread: Closing output stream FINE: LDAPConnThread: Closing input stream WARNING: LDAPConnThread: Unable to close input stream: Cannot invoke "java.io.InputStream.close()" because "this.m_serverInput" is null java.lang.NullPointerException: Cannot invoke "java.io.InputStream.close()" because "this.m_serverInput" is null at netscape.ldap.LDAPConnThread.close(Unknown Source) at netscape.ldap.LDAPConnection.close(Unknown Source) at com.netscape.cmscore.ldapconn.LdapBoundConnFactory.shutdown(LdapBoundConnFactory.java:617) at com.netscape.cmscore.dbs.DBSubsystem.shutdown(DBSubsystem.java:452) at org.dogtagpki.server.ca.cli.CACertImportCLI.execute(CACertImportCLI.java:200) at org.dogtagpki.cli.CommandCLI.execute(CommandCLI.java:58) at org.dogtagpki.cli.CLI.execute(CLI.java:357) at org.dogtagpki.cli.CLI.execute(CLI.java:357) at org.dogtagpki.cli.CLI.execute(CLI.java:357) at org.dogtagpki.server.cli.PKIServerCLI.execute(PKIServerCLI.java:93) at org.dogtagpki.server.cli.PKIServerCLI.main(PKIServerCLI.java:123) FINE: LDAPConnThread: Closing connection FINE: LdapBoundConnFactory: disconnecting master connection FINE: LDAPConnThread: Closing connection INFO: - serial: 0x4 INFO: Storing cert and request for subsystem INFO: Importing subsystem cert into NSS database DEBUG: NSSDatabase.add_cert(subsystemCert cert-pki-ca) DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpa2iyzx3x/password.txt nss-cert-import --format PEM --debug subsystemCert cert-pki-ca INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Storing password into /tmp/nss-password-15742917622566257310.txt FINE: NSSDatabase: Command: certutil -A -d /etc/pki/pki-tomcat/alias -f /tmp/nss-password-15742917622566257310.txt -a -n "subsystemCert cert-pki-ca" -t ,, -i /tmp/nss-cert-8415936137346206698.crt INFO: Setting up audit_signing cert DEBUG: PKISubsystem.get_subsystem_cert(audit_signing) INFO: Getting audit_signing cert info from CS.cfg DEBUG: PKISubsystem.get_nssdb_cert_info(audit_signing) INFO: Getting audit_signing cert info from NSS database DEBUG: NSSDatabase.get_cert_info(auditSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(auditSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmpvj_elpro/password.txt -n auditSigningCert cert-pki-ca -a DEBUG: Cert not found: auditSigningCert cert-pki-ca DEBUG: PKIDeployer.setup_system_cert() DEBUG: NSSDatabase.get_cert_info(auditSigningCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(auditSigningCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmpbr4fvzpy/password.txt -n auditSigningCert cert-pki-ca -a DEBUG: Cert not found: auditSigningCert cert-pki-ca INFO: audit_signing cert does not exist in NSS database INFO: Creating audit_signing key DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmp5_g_k7ha/password.txt nss-key-create --output-format json --key-type RSA --key-size 2048 --debug INFO: - key ID: 0xb90a82c4d0f8e32b7264e5a0e21b4da7789397fe INFO: Creating audit_signing cert request DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpa2iyzx3x/password.txt nss-cert-request --subject cn=CA Audit,O=REDACTED_DOMAIN.COM --csr /tmp/tmp1a9d9jmv/request.csr --key-id 0xb90a82c4d0f8e32b7264e5a0e21b4da7789397fe --hash SHA256 --debug INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Loading key 0xb90a82c4d0f8e32b7264e5a0e21b4da7789397fe FINE: NSSDatabase: - class: org.mozilla.jss.pkcs11.PK11RSAPrivateKey FINE: NSSDatabase: - algorithm: RSA FINE: NSSDatabase: - format: null FINE: NSSDatabase: - key type: RSA FINE: NSSDatabase: - size: 2048 FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: cn=CA Audit,O=REDACTED_DOMAIN.COM FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: cn=CA Audit,O=REDACTED_DOMAIN.COM FINE: CryptoUtil: - attributes: DEBUG: - request: MIICcjCCAVoCAQAwLTEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMREwDwYDVQQDDAhDQSBBdWRpdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJzXc5r32osXhmf49/RuCq3CUEoZHefLsCVy4zhzVNVTBgqrSjoSyCNtRiOqdAykrLbZU8Gz01ztcN5DgOZB0A++8Fdv9lYIOQp2ABOv1uLhqzGnk65QTxzoWUlx8jJWTtNesicm6a8BJ3JXhoV2dfvFi7EJHMozbZh+jai7g3XZzPInrG00vYqzzuPIjngest0zR6WWpx6S9A64O6c/wDy0OH0kxo5I/tGiWz9aqHQ2zz5Sb6X5JSElT2BXDy53YhvL3Ydx6Rt51D2BG93B5kqCbGOB5VgUNF36g+b8hrekMzV9cyNVVsrUfJ/JqSJaWUduLGYawT+/H4l8y3RA4XUCAwEAAaAAMA0GCSqGSIb3DQEBCwUAA4IBAQAfNw1ISRmGZ+ILxIMEfC04/38CqzinPGtJOlVgfu4boE/mr84gVwv/KN/LeeIN5K+9kylDEWbAKJYTnaG9mm4funO6/xmh97xAtRmp9saxKFAJhAkdqUW1Ha3s/gE8v0EbDM3mn9tM8tgsjVHnHXOOGXf7t1G0QhIvHO5lfxN0Ssr/aowVYvLNS2vT6Hv4+rgQl+NVq5PoRkezYlxiuAjbLhki7lVBSBSB4WE4wgj6fV5rOS1hrJNK5hkbQIvCxwdYOuX5UOPD1d/r/DI/sQBd6ft3yXXC58kkk9CNZ6GmqUFXEFWl7zfxnVgsFown9GNen9wjhP+axQ6pliZ+NTC9 INFO: Creating request ID for audit_signing cert INFO: - request ID: 0x5 INFO: Importing request for audit_signing cert DEBUG: Command: /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-request-import --debug --csr /tmp/tmptfbnvyof/cert.csr --type pkcs10 --profile caAuditSigningCert.profile --adjust-validity --output-format json 0x5 INFO: Importing /tmp/tmptfbnvyof/cert.csr INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/caAuditSigningCert.profile FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: Setting internaldb.basedn=o=ipaca FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(true) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: registered: false FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: null FINE: RequestRepository: - range DN: ou=requests,ou=ranges,o=ipaca FINE: RequestRepository: - min serial: 1 FINE: RequestRepository: - max serial: 10000000 FINE: RequestRepository: - next min serial: null FINE: RequestRepository: - next max serial: null FINE: CertRequestRepository: Creating request 0x5 FINE: CertRequestRepository: Updating request 0x5 FINE: CertRequestRepository: - type: pkcs10 FINE: CertRequestRepository: - request: -----BEGIN CERTIFICATE REQUEST----- MIICcjCCAVoCAQAwLTEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMREwDwYDVQQDDAhDQSBBdWRp dDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJzXc5r32osXhmf49/RuCq3CUEoZHefL sCVy4zhzVNVTBgqrSjoSyCNtRiOqdAykrLbZU8Gz01ztcN5DgOZB0A++8Fdv9lYIOQp2ABOv1uLh qzGnk65QTxzoWUlx8jJWTtNesicm6a8BJ3JXhoV2dfvFi7EJHMozbZh+jai7g3XZzPInrG00vYqz zuPIjngest0zR6WWpx6S9A64O6c/wDy0OH0kxo5I/tGiWz9aqHQ2zz5Sb6X5JSElT2BXDy53YhvL 3Ydx6Rt51D2BG93B5kqCbGOB5VgUNF36g+b8hrekMzV9cyNVVsrUfJ/JqSJaWUduLGYawT+/H4l8 y3RA4XUCAwEAAaAAMA0GCSqGSIb3DQEBCwUAA4IBAQAfNw1ISRmGZ+ILxIMEfC04/38CqzinPGtJ OlVgfu4boE/mr84gVwv/KN/LeeIN5K+9kylDEWbAKJYTnaG9mm4funO6/xmh97xAtRmp9saxKFAJ hAkdqUW1Ha3s/gE8v0EbDM3mn9tM8tgsjVHnHXOOGXf7t1G0QhIvHO5lfxN0Ssr/aowVYvLNS2vT 6Hv4+rgQl+NVq5PoRkezYlxiuAjbLhki7lVBSBSB4WE4wgj6fV5rOS1hrJNK5hkbQIvCxwdYOuX5 UOPD1d/r/DI/sQBd6ft3yXXC58kkk9CNZ6GmqUFXEFWl7zfxnVgsFown9GNen9wjhP+axQ6pliZ+ NTC9 -----END CERTIFICATE REQUEST----- FINE: CertRequestRepository: - subject: CN=CA Audit,O=REDACTED_DOMAIN.COM FINE: CertRequestRepository: Updating profile for request 0x5 FINE: CertRequestRepository: - profile: caAuditSigningCert.profile FINE: CertRequestRepository: - adjust validity: false FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Adding cn=5,ou=ca, ou=requests,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class request FINE: LDAPRegistry: Adding object class extensibleObject FINE: LDAPRegistry: Mapping attribute requestId FINE: RequestIdMapper: Mapping requestId to requestId FINE: LDAPRegistry: Mapping attribute requestState FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPRegistry: Mapping attribute requestCreateTime FINE: DateMapper: Mapping requestCreateTime to dateOfCreate FINE: LDAPRegistry: Mapping attribute requestModifyTime FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: LDAPRegistry: Skipping empty attribute requestSourceId FINE: LDAPRegistry: Skipping empty attribute requestOwner FINE: LDAPRegistry: Skipping empty attribute realm FINE: LDAPRegistry: Mapping attribute requestExtData FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPRegistry: Mapping attribute requestType FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - objectclass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(DBSubsystem) FINE: LDAPConnThread: Closing output stream FINE: LDAPConnThread: Closing connection FINE: LdapBoundConnFactory: disconnecting master connection FINE: LDAPConnThread: Closing connection INFO: Creating cert ID for audit_signing cert INFO: - cert ID: 0x5 INFO: Creating audit_signing cert INFO: Importing audit_signing cert DEBUG: - cert: MIID2DCCAkCgAwIBAgIBBTANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzUyNTVaFw0yNDEyMDYyMzUyNTVaMC0xGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTERMA8GA1UEAwwIQ0EgQXVkaXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCc13Oa99qLF4Zn+Pf0bgqtwlBKGR3ny7AlcuM4c1TVUwYKq0o6EsgjbUYjqnQMpKy22VPBs9Nc7XDeQ4DmQdAPvvBXb/ZWCDkKdgATr9bi4asxp5OuUE8c6FlJcfIyVk7TXrInJumvASdyV4aFdnX7xYuxCRzKM22Yfo2ou4N12czyJ6xtNL2Ks87jyI54HrLdM0ellqcekvQOuDunP8A8tDh9JMaOSP7Rols/Wqh0Ns8+Um+l+SUhJU9gVw8ud2Iby92HcekbedQ9gRvdweZKgmxjgeVYFDRd+oPm/Ia3pDM1fXMjVVbK1HyfyakiWllHbixmGsE/vx+JfMt0QOF1AgMBAAGjdjB0MB8GA1UdIwQYMBaAFJwhzOmncK9PBv2V/lhffsH2Z6HGMA4GA1UdDwEB/wQEAwIGwDBBBggrBgEFBQcBAQQ1MDMwMQYIKwYBBQUHMAGGJWh0dHA6Ly9pcGEtY2EubW9uaXZhZ3JvdXAuY29tL2NhL29jc3AwDQYJKoZIhvcNAQENBQADggGBAIn/LeFRiyAVab2CqrBeRtMB4+E6s2WVwlRLt//ElGdSdOeytmLgJ+WJRULLJiSx3EGxlieIe6J7RLdhVya422UmflrI/fPMPSWEWmiDYDUjMN8S2NonXRQjDJRIYqDnJi8ANkdjbkyWfhLKlGjrIhwPvvqoE5FCusno1yCbcrTXxnqpyEvOCN7tLOOexXtjWzoLXkaGyVXSDNyWD83n2cxdE8PqtoZPlqq5r+xu87h+Op64FePYN5b1djxMh4ixBSNXWP9VQntY7oUcuDp7yyTjRFYgqf8ptUeV5f2/8nrC24vi44rbs0GX+06CR5k6LPwSGMnF3aJK5kJrgk2HlXa0MEnDj1hjkYJlDl0LNzYlk/WX84uadxWO482quD3nszLkWdb1n4anzBBfhG9AgJjA96uvaEvc89go49s795de7HRHSNlVDe/qTDWy6cxRtfqSFC2bbpXOQbsAwhbzLerOhZrqIsIlWo4497ERA9h686p/Dm99P1IVdqHFWh9BdA== DEBUG: Command: /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-import --debug --cert /tmp/tmp0vqk3tnx/cert.crt --format PEM --request 0x5 --profile caAuditSigningCert.profile INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/caAuditSigningCert.profile FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: Setting internaldb.basedn=o=ipaca FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(true) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: registered: false FINE: CertificateRepository: Initializing certificate repository FINE: CertificateRepository: - base DN: ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - cert ID generator: null FINE: CertificateRepository: - range DN: ou=certificateRepository,ou=ranges,o=ipaca FINE: CertificateRepository: - min serial: 1 FINE: CertificateRepository: - max serial: 268435456 FINE: CertificateRepository: - next min serial: null FINE: CertificateRepository: - next max serial: null INFO: Creating cert record 0x5: INFO: - subject: CN=CA Audit,O=REDACTED_DOMAIN.COM INFO: - issuer: CN=Certificate Authority,O=REDACTED_DOMAIN.COM INFO: - request ID: 0x5 INFO: - profile ID mapping: caAuditSigningCert FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: CertificateRepository: Adding certificate record cn=5,ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - subject: CN=CA Audit,O=REDACTED_DOMAIN.COM FINE: CertificateRepository: - issuer: CN=Certificate Authority,O=REDACTED_DOMAIN.COM FINE: CertificateRepository: - issued by: system FINE: CertificateRepository: - status: VALID INFO: LDAPSession: Adding cn=5,ou=certificateRepository, ou=ca,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class certificateRecord FINE: LDAPRegistry: Mapping attribute certRecordId FINE: BigIntegerMapper: Mapping certRecordId to serialno FINE: LDAPRegistry: Mapping attribute certMetaInfo FINE: MetaInfoMapper: Mapping certMetaInfo to metaInfo FINE: LDAPRegistry: Skipping empty attribute certRevoInfo FINE: LDAPRegistry: Mapping attribute x509cert FINE: X509CertImplMapper: Mapping x509cert to notBefore FINE: X509CertImplMapper: Mapping x509cert to notAfter FINE: X509CertImplMapper: Mapping x509cert to duration FINE: X509CertImplMapper: Mapping x509cert to subjectName FINE: X509CertImplMapper: Mapping x509cert to issuerName FINE: X509CertImplMapper: Mapping x509cert to publicKeyData FINE: X509CertImplMapper: Mapping x509cert to extension FINE: X509CertImplMapper: Mapping x509cert to userCertificate;binary FINE: X509CertImplMapper: Mapping x509cert to version FINE: X509CertImplMapper: Mapping x509cert to algorithmId FINE: X509CertImplMapper: Mapping x509cert to signingAlgorithmId FINE: LDAPRegistry: Mapping attribute certCreateTime FINE: DateMapper: Mapping certCreateTime to dateOfCreate FINE: LDAPRegistry: Mapping attribute certModifyTime FINE: DateMapper: Mapping certModifyTime to dateOfModify FINE: LDAPRegistry: Mapping attribute certStatus FINE: StringMapper: Mapping certStatus to certStatus FINE: LDAPRegistry: Mapping attribute certAutoRenew FINE: StringMapper: Mapping certAutoRenew to autoRenew FINE: LDAPRegistry: Mapping attribute certIssuedBy FINE: StringMapper: Mapping certIssuedBy to issuedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedOn FINE: LDAPSession: - objectclass FINE: LDAPSession: - serialno FINE: LDAPSession: - metaInfo FINE: LDAPSession: - notBefore FINE: LDAPSession: - notAfter FINE: LDAPSession: - duration FINE: LDAPSession: - subjectName FINE: LDAPSession: - issuerName FINE: LDAPSession: - publicKeyData FINE: LDAPSession: - extension FINE: LDAPSession: - userCertificate;binary FINE: LDAPSession: - version FINE: LDAPSession: - algorithmId FINE: LDAPSession: - signingAlgorithmId FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - certStatus FINE: LDAPSession: - autoRenew FINE: LDAPSession: - issuedBy FINE: LdapBoundConnFactory: number of connections: 1 INFO: Updating request record 0x5 FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: null FINE: RequestRepository: - range DN: ou=requests,ou=ranges,o=ipaca FINE: RequestRepository: - min serial: 1 FINE: RequestRepository: - max serial: 10000000 FINE: RequestRepository: - next min serial: null FINE: RequestRepository: - next max serial: null FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Retrieving cn=5,ou=ca, ou=requests,o=ipaca FINE: LDAPSession: - objectClass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LDAPSession: - cn FINE: LdapBoundConnFactory: number of connections: 1 FINE: CertRequestRepository: Updating cert for request 0x5 FINE: CertRequestRepository: - cert serial number: 0x5 FINE: RequestRecord.loadExtDataFromRequest: missing subject name. Processing extracting subjectName from req_x509info FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Modifying cn=5,ou=ca, ou=requests,o=ipaca FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPSession: - replace: requestState FINE: StringMapper: Mapping requestSourceId to requestSourceId FINE: LDAPSession: - replace: requestSourceId FINE: StringMapper: Mapping requestOwner to requestOwner FINE: LDAPSession: - replace: requestOwner FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: LDAPSession: - replace: dateOfModify FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fissued--005fcert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fx509info FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPSession: - replace: extdata-req--005fissued--005fcert FINE: LDAPSession: - replace: extdata-profileapprovedby FINE: LDAPSession: - replace: extdata-origprofileid FINE: LDAPSession: - replace: extdata-cert--005frequest FINE: LDAPSession: - replace: extdata-profile FINE: LDAPSession: - replace: extdata-cert--005frequest--005ftype FINE: LDAPSession: - replace: extdata-requestversion FINE: LDAPSession: - replace: extdata-dbstatus FINE: LDAPSession: - replace: extdata-subject FINE: LDAPSession: - replace: extdata-requeststatus FINE: LDAPSession: - replace: extdata-isencryptioncert FINE: LDAPSession: - replace: extdata-req--005fkey FINE: LDAPSession: - replace: extdata-profileid FINE: LDAPSession: - replace: extdata-requestid FINE: LDAPSession: - replace: extdata-req--005fx509info FINE: LDAPSession: - replace: extdata-req--005fseq--005fnum FINE: LDAPSession: - replace: extdata-profilesetid FINE: LDAPSession: - replace: extdata-requesttype FINE: LDAPSession: - replace: extdata-req--005fextensions FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - replace: requestType FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(DBSubsystem) FINE: LDAPConnThread: Closing output stream FINE: LDAPConnThread: Closing input stream FINE: LDAPConnThread: Closing connection FINE: LdapBoundConnFactory: disconnecting master connection FINE: LDAPConnThread: Closing connection INFO: - serial: 0x5 INFO: Storing cert and request for audit_signing INFO: Importing audit_signing cert into NSS database DEBUG: NSSDatabase.add_cert(auditSigningCert cert-pki-ca) DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpa2iyzx3x/password.txt nss-cert-import --format PEM --debug auditSigningCert cert-pki-ca INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Storing password into /tmp/nss-password-708988330245978779.txt FINE: NSSDatabase: Command: certutil -A -d /etc/pki/pki-tomcat/alias -f /tmp/nss-password-708988330245978779.txt -a -n "auditSigningCert cert-pki-ca" -t ,, -i /tmp/nss-cert-15948924758802336536.crt INFO: Setting up trust flags DEBUG: Command: certutil -M -d /etc/pki/pki-tomcat/alias -f /tmp/tmpa2iyzx3x/password.txt -n caSigningCert cert-pki-ca -t CTu,Cu,Cu DEBUG: Command: certutil -M -d /etc/pki/pki-tomcat/alias -f /tmp/tmpa2iyzx3x/password.txt -n auditSigningCert cert-pki-ca -t u,u,Pu INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Setting up subsystem user INFO: Adding CA-master.redacted_domain.com-8443 DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-add --full-name CA-master.redacted_domain.com-8443 --type agentType --state 1 --debug CA-master.redacted_domain.com-8443 FINE: SubsystemUserAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 INFO: Adding uid=CA-master.redacted_domain.com-8443,ou=People,o=ipaca FINE: UGSubsystem: - objectclass: [top, person, organizationalPerson, inetOrgPerson, cmsuser] FINE: UGSubsystem: - uid: CA-master.redacted_domain.com-8443 FINE: UGSubsystem: - sn: CA-master.redacted_domain.com-8443 FINE: UGSubsystem: - cn: CA-master.redacted_domain.com-8443 FINE: UGSubsystem: - usertype: agentType FINE: UGSubsystem: - userstate: 1 INFO: Admin UID: null added User UID: CA-master.redacted_domain.com-8443 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Adding certificate for CA-master.redacted_domain.com-8443 DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-cert-add --format PEM --debug CA-master.redacted_domain.com-8443 FINE: SubsystemUserCertAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: Admin UID: null added cert for User UID: CA-master.redacted_domain.com-8443. cert DN: CN=CA Subsystem,O=REDACTED_DOMAIN.COM serial number: 0x4 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Adding CA-master.redacted_domain.com-8443 into Subsystem Group DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Subsystem Group CA-master.redacted_domain.com-8443 FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Subsystem Group,ou=Groups,o=ipaca FINE: description: Subsystem Group FINE: uniqueMember: uid=CA-master.redacted_domain.com-8443,ou=People,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Getting admin certificate DEBUG: PKIDeployer.get_admin_cert() DEBUG: PKIDeployer: pki_external_step_two: False INFO: Generating CSR for cn=ipa-ca-agent,O=REDACTED_DOMAIN.COM DEBUG: Command: certutil -R -d /root/.dogtag/pki-tomcat/ca/alias -s cn=ipa-ca-agent,O=REDACTED_DOMAIN.COM -k rsa -g 2048 -z /root/.dogtag/pki-tomcat/ca/alias/noise -f /root/.dogtag/pki-tomcat/ca/password.conf -o /root/.dogtag/pki-tomcat/ca/alias/admin_pkcs10.bin INFO: Removing /root/.dogtag/pki-tomcat/ca/alias/noise DEBUG: Command: rm -f /root/.dogtag/pki-tomcat/ca/alias/noise DEBUG: Command: BtoA /root/.dogtag/pki-tomcat/ca/alias/admin_pkcs10.bin /root/.dogtag/pki-tomcat/ca/alias/admin_pkcs10.bin.asc INFO: Loading /var/lib/pki/pki-tomcat/ca/profiles/ca/caAdminCert.cfg INFO: Key type: RSA INFO: Allowed signing algorithms: SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC,SHA256withRSA/PSS,SHA384withRSA/PSS,SHA512withRSA/PSS INFO: Signing algorithm: SHA256withRSA INFO: Creating request ID for admin cert INFO: - request ID: 0x6 INFO: Importing request for admin cert DEBUG: Command: /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-request-import --debug --csr /tmp/tmpqo1mjzn3/cert.csr --type pkcs10 --profile adminCert.profile --output-format json 0x6 INFO: Importing /tmp/tmpqo1mjzn3/cert.csr INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/adminCert.profile FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: Setting internaldb.basedn=o=ipaca FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(true) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: registered: false FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: null FINE: RequestRepository: - range DN: ou=requests,ou=ranges,o=ipaca FINE: RequestRepository: - min serial: 1 FINE: RequestRepository: - max serial: 10000000 FINE: RequestRepository: - next min serial: null FINE: RequestRepository: - next max serial: null FINE: CertRequestRepository: Creating request 0x6 FINE: CertRequestRepository: Updating request 0x6 FINE: CertRequestRepository: - type: pkcs10 FINE: CertRequestRepository: - request: -----BEGIN CERTIFICATE REQUEST----- MIICdjCCAV4CAQAwMTEYMBYGA1UEChMPTU9OSVZBR1JPVVAuQ09NMRUwEwYDVQQDEwxpcGEtY2Et YWdlbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCh66GfnmI8XsDgizoEvDDTG9mW 3p2s41avSsIon+jMP1Yo+34wGWAbYngyyviKbjAP4ZzLSkZUQhnYJP6tCqy3dyThgtq2ZUYCoL8m /0hjYDKjkKttFOpGfmVnF0/9yWQU0Sl6j5jMNwlk7hE0dZbHrq7y0kEJWqHbmH2VJV8n5XQ3ANpK ezQH+cpwKXCHn3tFa24pJMmUxC7QbTHIWNgugBQk6MDe6TzI0F2k/cOluZgasCdy18V6oBKt29Ye 4AM8w3rnxA3+DyXPvYa2wKo0BQA4qdOMxfwylHgy0RSEMcN0TRicV1c4QdTm/SG01HYdnbf7ECDs Q3USJSDvceyLAgMBAAGgADANBgkqhkiG9w0BAQsFAAOCAQEAXvXIn2raA4+v9nKJF6tBB73cpEc+ 56K4LZInTv45WFlPejtE66yTZcB0csAqcSeiL2+UQkcoRAhplqEh2Auk+C71EgfVUidY3/tDDv9F acMk1dM04BYELNSDI8xXwf2SzM0+R7+mPwdnBweu8LFBLUIM/wN+AlfxhlddqgUnoCmkAo6aXbES /7Xyk32navwJk0gL0FJsqLB4OhmbVFDBlQvX8TaTDFrURKq0HW42uBuLdoj8OwrbbDQ0FOgFyy/k Wos2wbZGn1oejncq14H+LEcqH3fXbfudo8xsygla9unpt812nSCplDOD/WFDbyMgOFU4+4NSq/J3 X/F5tHAYAQ== -----END CERTIFICATE REQUEST----- FINE: CertRequestRepository: - subject: CN=ipa-ca-agent,O=REDACTED_DOMAIN.COM FINE: CertRequestRepository: Updating profile for request 0x6 FINE: CertRequestRepository: - profile: adminCert.profile FINE: CertRequestRepository: - adjust validity: false FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Adding cn=6,ou=ca, ou=requests,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class request FINE: LDAPRegistry: Adding object class extensibleObject FINE: LDAPRegistry: Mapping attribute requestId FINE: RequestIdMapper: Mapping requestId to requestId FINE: LDAPRegistry: Mapping attribute requestState FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPRegistry: Mapping attribute requestCreateTime FINE: DateMapper: Mapping requestCreateTime to dateOfCreate FINE: LDAPRegistry: Mapping attribute requestModifyTime FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: LDAPRegistry: Skipping empty attribute requestSourceId FINE: LDAPRegistry: Skipping empty attribute requestOwner FINE: LDAPRegistry: Skipping empty attribute realm FINE: LDAPRegistry: Mapping attribute requestExtData FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPRegistry: Mapping attribute requestType FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - objectclass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(DBSubsystem) FINE: LDAPConnThread: Closing output stream FINE: LDAPConnThread: Closing connection FINE: LdapBoundConnFactory: disconnecting master connection FINE: LDAPConnThread: Closing connection INFO: Creating cert ID for admin cert INFO: - cert ID: 0x6 INFO: Creating admin cert INFO: Importing admin cert DEBUG: - cert: MIID/TCCAmWgAwIBAgIBBjANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzUzMDVaFw0yNDEyMDYyMzUzMDVaMDExGDAWBgNVBAoTD01PTklWQUdST1VQLkNPTTEVMBMGA1UEAxMMaXBhLWNhLWFnZW50MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoeuhn55iPF7A4Is6BLww0xvZlt6drONWr0rCKJ/ozD9WKPt+MBlgG2J4Msr4im4wD+Gcy0pGVEIZ2CT+rQqst3ck4YLatmVGAqC/Jv9IY2Ayo5CrbRTqRn5lZxdP/clkFNEpeo+YzDcJZO4RNHWWx66u8tJBCVqh25h9lSVfJ+V0NwDaSns0B/nKcClwh597RWtuKSTJlMQu0G0xyFjYLoAUJOjA3uk8yNBdpP3DpbmYGrAnctfFeqASrdvWHuADPMN658QN/g8lz72GtsCqNAUAOKnTjMX8MpR4MtEUhDHDdE0YnFdXOEHU5v0htNR2HZ23+xAg7EN1EiUg73HsiwIDAQABo4GWMIGTMB8GA1UdIwQYMBaAFJwhzOmncK9PBv2V/lhffsH2Z6HGMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL2lwYS1jYS5tb25pdmFncm91cC5jb20vY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBeAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMA0GCSqGSIb3DQEBDQUAA4IBgQBcUZtLXy4KkjlSHbrSd/N0AsU7BrnHb4AmF6MEdwuNueD9ertNYtYDU+HJF2MHWHxvfmeMCw0iGtJbfEfOn5Kjp1tH8ZNZqS61r2nS6kN1PiMByAuNHbADr8G2ccB7DandX5PAuvn+PhHcAtNJ2du2xZfy8amTyxHYnYgxq4dBgpHlylLRm1N9RMtUVPu9ojg5JndR6/7+LL7iX+F5DTT1moyaLHofD9qmgsilWs2GMwTEv5X7viC8UdbrLuPm/rCaLKgqWn3kf7TJYuS7nEad0lVC+CXt4I7GmfEndNfBwOjtS8FIi5ONNk4dYiSYp0k0dWi7qmP9CyAE1DQB32JWQ5ZiARxbnoilh6wmVxdkZ4G8kYBTf2VaHc6eKhOghcqaei3i9lshTEIqyCcpbOixslGbmslf4VnTDRavoQngayi4sy5Wza10BbjY18sKvww6FCL6f5o00C+bgKJ6zEyvapV7zcXKpuJwjcyEb63mW67owUIM9iVbRt1r9G9z7+I= DEBUG: Command: /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-cert-import --debug --cert /tmp/tmpfb6kby66/cert.crt --format PEM --request 0x6 --profile adminCert.profile INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/adminCert.profile FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: DBSubsystem: init() mEnableSerialMgmt=false FINE: Creating LdapBoundConnFactor(DBSubsystem) FINE: Setting internaldb.basedn=o=ipaca FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(true) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: registered: false FINE: CertificateRepository: Initializing certificate repository FINE: CertificateRepository: - base DN: ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - cert ID generator: null FINE: CertificateRepository: - range DN: ou=certificateRepository,ou=ranges,o=ipaca FINE: CertificateRepository: - min serial: 1 FINE: CertificateRepository: - max serial: 268435456 FINE: CertificateRepository: - next min serial: null FINE: CertificateRepository: - next max serial: null INFO: Creating cert record 0x6: INFO: - subject: CN=ipa-ca-agent,O=REDACTED_DOMAIN.COM INFO: - issuer: CN=Certificate Authority,O=REDACTED_DOMAIN.COM INFO: - request ID: 0x6 INFO: - profile ID mapping: caAdminCert FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: CertificateRepository: Adding certificate record cn=6,ou=certificateRepository, ou=ca,o=ipaca FINE: CertificateRepository: - subject: CN=ipa-ca-agent,O=REDACTED_DOMAIN.COM FINE: CertificateRepository: - issuer: CN=Certificate Authority,O=REDACTED_DOMAIN.COM FINE: CertificateRepository: - issued by: system FINE: CertificateRepository: - status: VALID INFO: LDAPSession: Adding cn=6,ou=certificateRepository, ou=ca,o=ipaca FINE: LDAPRegistry: Adding object class top FINE: LDAPRegistry: Adding object class certificateRecord FINE: LDAPRegistry: Mapping attribute certRecordId FINE: BigIntegerMapper: Mapping certRecordId to serialno FINE: LDAPRegistry: Mapping attribute certMetaInfo FINE: MetaInfoMapper: Mapping certMetaInfo to metaInfo FINE: LDAPRegistry: Skipping empty attribute certRevoInfo FINE: LDAPRegistry: Mapping attribute x509cert FINE: X509CertImplMapper: Mapping x509cert to notBefore FINE: X509CertImplMapper: Mapping x509cert to notAfter FINE: X509CertImplMapper: Mapping x509cert to duration FINE: X509CertImplMapper: Mapping x509cert to subjectName FINE: X509CertImplMapper: Mapping x509cert to issuerName FINE: X509CertImplMapper: Mapping x509cert to publicKeyData FINE: X509CertImplMapper: Mapping x509cert to extension FINE: X509CertImplMapper: Mapping x509cert to userCertificate;binary FINE: X509CertImplMapper: Mapping x509cert to version FINE: X509CertImplMapper: Mapping x509cert to algorithmId FINE: X509CertImplMapper: Mapping x509cert to signingAlgorithmId FINE: LDAPRegistry: Mapping attribute certCreateTime FINE: DateMapper: Mapping certCreateTime to dateOfCreate FINE: LDAPRegistry: Mapping attribute certModifyTime FINE: DateMapper: Mapping certModifyTime to dateOfModify FINE: LDAPRegistry: Mapping attribute certStatus FINE: StringMapper: Mapping certStatus to certStatus FINE: LDAPRegistry: Mapping attribute certAutoRenew FINE: StringMapper: Mapping certAutoRenew to autoRenew FINE: LDAPRegistry: Mapping attribute certIssuedBy FINE: StringMapper: Mapping certIssuedBy to issuedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedBy FINE: LDAPRegistry: Skipping empty attribute certRevokedOn FINE: LDAPSession: - objectclass FINE: LDAPSession: - serialno FINE: LDAPSession: - metaInfo FINE: LDAPSession: - notBefore FINE: LDAPSession: - notAfter FINE: LDAPSession: - duration FINE: LDAPSession: - subjectName FINE: LDAPSession: - issuerName FINE: LDAPSession: - publicKeyData FINE: LDAPSession: - extension FINE: LDAPSession: - userCertificate;binary FINE: LDAPSession: - version FINE: LDAPSession: - algorithmId FINE: LDAPSession: - signingAlgorithmId FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - certStatus FINE: LDAPSession: - autoRenew FINE: LDAPSession: - issuedBy FINE: LdapBoundConnFactory: number of connections: 1 INFO: Updating request record 0x6 FINE: RequestRepository: Initializing request repository FINE: RequestRepository: - filter: (requeststate=*) FINE: RequestRepository: - base DN: ou=ca, ou=requests,o=ipaca FINE: RequestRepository: - request ID generator: null FINE: RequestRepository: - range DN: ou=requests,ou=ranges,o=ipaca FINE: RequestRepository: - min serial: 1 FINE: RequestRepository: - max serial: 10000000 FINE: RequestRepository: - next min serial: null FINE: RequestRepository: - next max serial: null FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Retrieving cn=6,ou=ca, ou=requests,o=ipaca FINE: LDAPSession: - objectClass FINE: LDAPSession: - requestId FINE: LDAPSession: - requestState FINE: LDAPSession: - dateOfCreate FINE: LDAPSession: - dateOfModify FINE: LDAPSession: - extdata-profileapprovedby FINE: LDAPSession: - extdata-origprofileid FINE: LDAPSession: - extdata-cert--005frequest FINE: LDAPSession: - extdata-profile FINE: LDAPSession: - extdata-cert--005frequest--005ftype FINE: LDAPSession: - extdata-requestversion FINE: LDAPSession: - extdata-subject FINE: LDAPSession: - extdata-dbstatus FINE: LDAPSession: - extdata-requeststatus FINE: LDAPSession: - extdata-isencryptioncert FINE: LDAPSession: - extdata-req--005fkey FINE: LDAPSession: - extdata-profileid FINE: LDAPSession: - extdata-requestid FINE: LDAPSession: - extdata-req--005fseq--005fnum FINE: LDAPSession: - extdata-profilesetid FINE: LDAPSession: - extdata-requesttype FINE: LDAPSession: - extdata-req--005fextensions FINE: LDAPSession: - requestType FINE: LDAPSession: - cn FINE: LdapBoundConnFactory: number of connections: 1 FINE: CertRequestRepository: Updating cert for request 0x6 FINE: CertRequestRepository: - cert serial number: 0x6 FINE: RequestRecord.loadExtDataFromRequest: missing subject name. Processing extracting subjectName from req_x509info FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: LDAPSession: Modifying cn=6,ou=ca, ou=requests,o=ipaca FINE: RequestStateMapper: Mapping requestState to requestState FINE: LDAPSession: - replace: requestState FINE: StringMapper: Mapping requestSourceId to requestSourceId FINE: LDAPSession: - replace: requestSourceId FINE: StringMapper: Mapping requestOwner to requestOwner FINE: LDAPSession: - replace: requestOwner FINE: DateMapper: Mapping requestModifyTime to dateOfModify FINE: LDAPSession: - replace: dateOfModify FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fissued--005fcert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileapprovedby FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-origprofileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profile FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-cert--005frequest--005ftype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestversion FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-dbstatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-subject FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requeststatus FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-isencryptioncert FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fkey FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profileid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requestid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fx509info FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fseq--005fnum FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-profilesetid FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-requesttype FINE: ExtAttrDynMapper: Mapping requestExtData to extdata-req--005fextensions FINE: LDAPSession: - replace: extdata-req--005fissued--005fcert FINE: LDAPSession: - replace: extdata-profileapprovedby FINE: LDAPSession: - replace: extdata-origprofileid FINE: LDAPSession: - replace: extdata-cert--005frequest FINE: LDAPSession: - replace: extdata-profile FINE: LDAPSession: - replace: extdata-cert--005frequest--005ftype FINE: LDAPSession: - replace: extdata-requestversion FINE: LDAPSession: - replace: extdata-dbstatus FINE: LDAPSession: - replace: extdata-subject FINE: LDAPSession: - replace: extdata-requeststatus FINE: LDAPSession: - replace: extdata-isencryptioncert FINE: LDAPSession: - replace: extdata-req--005fkey FINE: LDAPSession: - replace: extdata-profileid FINE: LDAPSession: - replace: extdata-requestid FINE: LDAPSession: - replace: extdata-req--005fx509info FINE: LDAPSession: - replace: extdata-req--005fseq--005fnum FINE: LDAPSession: - replace: extdata-profilesetid FINE: LDAPSession: - replace: extdata-requesttype FINE: LDAPSession: - replace: extdata-req--005fextensions FINE: StringMapper: Mapping requestType to requestType FINE: LDAPSession: - replace: requestType FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(DBSubsystem) FINE: LDAPConnThread: Closing output stream FINE: LDAPConnThread: Closing input stream FINE: LDAPConnThread: Closing connection FINE: LdapBoundConnFactory: disconnecting master connection FINE: LDAPConnThread: Closing connection INFO: - serial: 0x6 DEBUG: Admin cert: MIID/TCCAmWgAwIBAgIBBjANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzUzMDVaFw0yNDEyMDYyMzUzMDVaMDExGDAWBgNVBAoTD01PTklWQUdST1VQLkNPTTEVMBMGA1UEAxMMaXBhLWNhLWFnZW50MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoeuhn55iPF7A4Is6BLww0xvZlt6drONWr0rCKJ/ozD9WKPt+MBlgG2J4Msr4im4wD+Gcy0pGVEIZ2CT+rQqst3ck4YLatmVGAqC/Jv9IY2Ayo5CrbRTqRn5lZxdP/clkFNEpeo+YzDcJZO4RNHWWx66u8tJBCVqh25h9lSVfJ+V0NwDaSns0B/nKcClwh597RWtuKSTJlMQu0G0xyFjYLoAUJOjA3uk8yNBdpP3DpbmYGrAnctfFeqASrdvWHuADPMN658QN/g8lz72GtsCqNAUAOKnTjMX8MpR4MtEUhDHDdE0YnFdXOEHU5v0htNR2HZ23+xAg7EN1EiUg73HsiwIDAQABo4GWMIGTMB8GA1UdIwQYMBaAFJwhzOmncK9PBv2V/lhffsH2Z6HGMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL2lwYS1jYS5tb25pdmFncm91cC5jb20vY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBeAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMA0GCSqGSIb3DQEBDQUAA4IBgQBcUZtLXy4KkjlSHbrSd/N0AsU7BrnHb4AmF6MEdwuNueD9ertNYtYDU+HJF2MHWHxvfmeMCw0iGtJbfEfOn5Kjp1tH8ZNZqS61r2nS6kN1PiMByAuNHbADr8G2ccB7DandX5PAuvn+PhHcAtNJ2du2xZfy8amTyxHYnYgxq4dBgpHlylLRm1N9RMtUVPu9ojg5JndR6/7+LL7iX+F5DTT1moyaLHofD9qmgsilWs2GMwTEv5X7viC8UdbrLuPm/rCaLKgqWn3kf7TJYuS7nEad0lVC+CXt4I7GmfEndNfBwOjtS8FIi5ONNk4dYiSYp0k0dWi7qmP9CyAE1DQB32JWQ5ZiARxbnoilh6wmVxdkZ4G8kYBTf2VaHc6eKhOghcqaei3i9lshTEIqyCcpbOixslGbmslf4VnTDRavoQngayi4sy5Wza10BbjY18sKvww6FCL6f5o00C+bgKJ6zEyvapV7zcXKpuJwjcyEb63mW67owUIM9iVbRt1r9G9z7+I= INFO: Storing admin cert into /root/.dogtag/pki-tomcat/ca_admin.cert INFO: Importing admin cert into /root/.dogtag/pki-tomcat/ca/alias DEBUG: NSSDatabase.add_cert(ipa-ca-agent) DEBUG: Command: certutil -A -d /root/.dogtag/pki-tomcat/ca/alias -f /root/.dogtag/pki-tomcat/ca/password.conf -n ipa-ca-agent -a -i /root/.dogtag/pki-tomcat/ca_admin.cert -t ,, INFO: Exporting admin cert into /root/ca-agent.p12 INFO: Creating /root INFO: Exporting ipa-ca-agent cert and key into /root/ca-agent.p12 DEBUG: Command: pk12util -d /root/.dogtag/pki-tomcat/ca/alias -o /root/ca-agent.p12 -n ipa-ca-agent -w /root/.dogtag/pki-tomcat/ca/pkcs12_password.conf -k /root/.dogtag/pki-tomcat/ca/password.conf -c AES-128-CBC -C NONE INFO: Setting up admin user DEBUG: Command: /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-add --full-name admin --email root@localhost --password-file /tmp/tmp2t0dajen/password.txt --type adminType --state 1 --debug admin FINE: SubsystemUserAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 INFO: Adding uid=admin,ou=People,o=ipaca FINE: UGSubsystem: - objectclass: [top, person, organizationalPerson, inetOrgPerson, cmsuser] FINE: UGSubsystem: - uid: admin FINE: UGSubsystem: - sn: admin FINE: UGSubsystem: - cn: admin FINE: UGSubsystem: - mail: root@localhost FINE: UGSubsystem: - userPassword: ******** FINE: UGSubsystem: - usertype: adminType FINE: UGSubsystem: - userstate: 1 INFO: Admin UID: null added User UID: admin FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Adding admin into Certificate Manager Agents DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Certificate Manager Agents admin FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Certificate Manager Agents,ou=Groups,o=ipaca FINE: description: Agents for Certificate Manager FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Adding admin into Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Administrators admin FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Administrators,ou=Groups,o=ipaca FINE: description: People who manage the Certificate System FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Adding admin into Security Domain Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Security Domain Administrators admin FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Security Domain Administrators,ou=Groups,o=ipaca FINE: description: People who are the Security Domain administrators FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Adding admin into Enterprise CA Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Enterprise CA Administrators admin FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Enterprise CA Administrators,ou=Groups,o=ipaca FINE: description: People who are the administrators for the security domain for CA FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Adding admin into Enterprise KRA Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Enterprise KRA Administrators admin FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Enterprise KRA Administrators,ou=Groups,o=ipaca FINE: description: People who are the administrators for the security domain for KRA FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Adding admin into Enterprise RA Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Enterprise RA Administrators admin FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Enterprise RA Administrators,ou=Groups,o=ipaca FINE: description: People who are the administrators for the security domain for RA FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Adding admin into Enterprise TKS Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Enterprise TKS Administrators admin FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Enterprise TKS Administrators,ou=Groups,o=ipaca FINE: description: People who are the administrators for the security domain for TKS FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Adding admin into Enterprise OCSP Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Enterprise OCSP Administrators admin FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Enterprise OCSP Administrators,ou=Groups,o=ipaca FINE: description: People who are the administrators for the security domain for OCSP FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Adding admin into Enterprise TPS Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Enterprise TPS Administrators admin FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Enterprise TPS Administrators,ou=Groups,o=ipaca FINE: description: People who are the administrators for the security domain for TPS FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Adding certificate for admin DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-cert-add --format DER --debug admin FINE: SubsystemUserCertAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: Admin UID: null added cert for User UID: admin. cert DN: CN=ipa-ca-agent,O=REDACTED_DOMAIN.COM serial number: 0x6 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Creating security domain DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-sd-create --debug INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager INFO: Adding ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSecurityDomain FINE: - name: IPA FINE: - ou: Security Domain INFO: Adding cn=CAList,ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSecurityGroup FINE: - cn: CAList INFO: Adding cn=OCSPList,ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSecurityGroup FINE: - cn: OCSPList INFO: Adding cn=KRAList,ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSecurityGroup FINE: - cn: KRAList INFO: Adding cn=RAList,ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSecurityGroup FINE: - cn: RAList INFO: Adding cn=TKSList,ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSecurityGroup FINE: - cn: TKSList INFO: Adding cn=TPSList,ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSecurityGroup FINE: - cn: TPSList INFO: Adding security domain manager DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-sd-host-add --hostname master.redacted_domain.com --unsecure-port 80 --secure-port 443 --domain-manager --debug CA master.redacted_domain.com 8443 INFO: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager INFO: Adding cn=master.redacted_domain.com:443,cn=CAList,ou=Security Domain,o=ipaca FINE: - objectclass: top FINE: - objectclass: pkiSubsystem FINE: - cn: master.redacted_domain.com:443 FINE: - SubsystemName: CA master.redacted_domain.com 8443 FINE: - Host: master.redacted_domain.com FINE: - UnSecurePort: 80 FINE: - SecurePort: 443 FINE: - SecureAgentPort: 443 FINE: - SecureAdminPort: 443 FINE: - SecureEEClientAuthPort: 443 FINE: - DomainManager: TRUE FINE: - Clone: FALSE INFO: Setting up database user INFO: Adding pkidbuser DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-add --full-name pkidbuser --type agentType --state 1 --debug pkidbuser FINE: SubsystemUserAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 INFO: Adding uid=pkidbuser,ou=People,o=ipaca FINE: UGSubsystem: - objectclass: [top, person, organizationalPerson, inetOrgPerson, cmsuser] FINE: UGSubsystem: - uid: pkidbuser FINE: UGSubsystem: - sn: pkidbuser FINE: UGSubsystem: - cn: pkidbuser FINE: UGSubsystem: - usertype: agentType FINE: UGSubsystem: - userstate: 1 INFO: Admin UID: null added User UID: pkidbuser FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection DEBUG: PKISubsystem.get_subsystem_cert(subsystem) INFO: Getting subsystem cert info from CS.cfg DEBUG: PKISubsystem.get_nssdb_cert_info(subsystem) INFO: Getting subsystem cert info from NSS database DEBUG: NSSDatabase.get_cert_info(subsystemCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmp989v4k97/password.txt -n subsystemCert cert-pki-ca -a DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) ends DEBUG: NSSDatabase.get_trust(subsystemCert cert-pki-ca) DEBUG: fullname: subsystemCert cert-pki-ca DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmp9c78cc0p/password.txt DEBUG: NSSDatabase.get_cert_info(subsystemCert cert-pki-ca) ends DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmpy8ezz00p/password.txt -n subsystemCert cert-pki-ca -a DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) ends INFO: Adding subsystem cert into pkidbuser DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-cert-add --format PEM --debug pkidbuser FINE: SubsystemUserCertAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: Admin UID: null added cert for User UID: pkidbuser. cert DN: CN=CA Subsystem,O=REDACTED_DOMAIN.COM serial number: 0x4 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Linking pkidbuser to subsystem cert: CN=CA Subsystem,O=REDACTED_DOMAIN.COM DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-mod --add-see-also CN=CA Subsystem,O=REDACTED_DOMAIN.COM --debug pkidbuser FINE: SubsystemUserModifyCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: Admin UID: null added cert subject DN for User UID: pkidbuser. cert DN: CN=CA Subsystem,O=REDACTED_DOMAIN.COM FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection FINE: Destroying LdapBoundConnFactory(UGSubsystem) INFO: Finding other users linked to subsystem cert DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-user-find --see-also CN=CA Subsystem,O=REDACTED_DOMAIN.COM --debug --output-format json FINE: SubsystemUserFindCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 INFO: LDAP: search ou=People,o=ipaca with (seeAlso=CN=CA Subsystem,O=REDACTED_DOMAIN.COM) FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Adding pkidbuser into Subsystem Group DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Subsystem Group pkidbuser FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Subsystem Group,ou=Groups,o=ipaca FINE: description: Subsystem Group FINE: uniqueMember: uid=CA-master.redacted_domain.com-8443,ou=People,o=ipaca FINE: uniqueMember: uid=pkidbuser,ou=People,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Adding pkidbuser into Certificate Manager Agents DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-group-member-add --debug Certificate Manager Agents pkidbuser FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 389 FINE: LdapBoundConnFactory: secure: false FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Certificate Manager Agents,ou=Groups,o=ipaca FINE: description: Agents for Certificate Manager FINE: uniqueMember: uid=admin,ou=People,o=ipaca FINE: uniqueMember: uid=pkidbuser,ou=People,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection INFO: Updating CA ranges DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/ca/webapps/ca/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI ca-range-update --debug FINE: SubsystemRangeUpdateCLI: Loading /var/lib/pki/pki-tomcat/ca/conf/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:389 with basic auth as cn=Directory Manager INFO: Updating serial number range INFO: Updating request number range INFO: Starting CRL number: 0 INFO: Enabling profile subsystem INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: CA configuration complete INFO: Stopping PKI server DEBUG: Command: systemctl stop pki-tomcatd@pki-tomcat.service INFO: Waiting for PKI server to stop INFO: PKI server stopped INFO: Removing temp SSL server cert from internal token: Server-Cert cert-pki-ca DEBUG: Command: certutil -D -d /etc/pki/pki-tomcat/alias -f /tmp/tmpxdvt2g82/password.txt -n Server-Cert cert-pki-ca INFO: Importing permanent SSL server cert into internal token: Server-Cert cert-pki-ca DEBUG: NSSDatabase.add_cert(Server-Cert cert-pki-ca) DEBUG: Command: certutil -A -d /etc/pki/pki-tomcat/alias -f /tmp/tmpr3atrb74/internal_password.txt -n Server-Cert cert-pki-ca -a -i /tmp/tmpffd3zrkl/sslserver.crt -t ,, INFO: Starting PKI server DEBUG: Command: systemctl start pki-tomcatd@pki-tomcat.service INFO: Waiting for PKI server to start INFO: Waiting for PKI server to start (1s) INFO: PKI server started INFO: Waiting for CA subsystem INFO: Subsystem status: running INFO: Finalizing subsystem creation INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /etc/pki/pki-tomcat/tomcat.conf INFO: Loading password config: /etc/pki/pki-tomcat/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser INFO: Backing up keys into /etc/pki/pki-tomcat/alias/ca_backup_keys.p12 DEBUG: Command: pki-server subsystem-cert-export ca -i pki-tomcat --pkcs12-file /etc/pki/pki-tomcat/alias/ca_backup_keys.p12 --pkcs12-password-file /tmp/tmpoz6hxpm7/password.txt WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. DEBUG: Command: systemctl enable pki-tomcatd@pki-tomcat.service INFO: Removing directory /root/.dogtag/pki-tomcat/ca DEBUG: Command: rm -rf /root/.dogtag/pki-tomcat/ca INFO: END spawning CA subsystem in pki-tomcat instance INFO: Creating /var/log/pki/pki-tomcat/ca/archive/spawn_deployment.cfg.20221218005131 DEBUG: Command: cp -p /etc/sysconfig/pki/tomcat/pki-tomcat/ca/deployment.cfg /var/log/pki/pki-tomcat/ca/archive/spawn_deployment.cfg.20221218005131 DEBUG: Command: chmod 660 /var/log/pki/pki-tomcat/ca/archive/spawn_deployment.cfg.20221218005131 DEBUG: Command: chown 17:17 /var/log/pki/pki-tomcat/ca/archive/spawn_deployment.cfg.20221218005131 INFO: Creating /var/log/pki/pki-tomcat/ca/archive/spawn_manifest.20221218005131 DEBUG: Command: cp -p /etc/sysconfig/pki/tomcat/pki-tomcat/ca/manifest /var/log/pki/pki-tomcat/ca/archive/spawn_manifest.20221218005131 DEBUG: Command: chmod 660 /var/log/pki/pki-tomcat/ca/archive/spawn_manifest.20221218005131 DEBUG: Command: chown 17:17 /var/log/pki/pki-tomcat/ca/archive/spawn_manifest.20221218005131 2022-12-17T23:53:55Z DEBUG completed creating ca instance 2022-12-17T23:53:55Z DEBUG step duration: pki-tomcatd __spawn_instance 144.00 sec 2022-12-17T23:53:55Z DEBUG [2/30]: stopping certificate server instance to update CS.cfg 2022-12-17T23:53:55Z DEBUG Starting external process 2022-12-17T23:53:55Z DEBUG args=['/bin/systemctl', 'stop', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:53:56Z DEBUG Process finished, return code=0 2022-12-17T23:53:56Z DEBUG stdout= 2022-12-17T23:53:56Z DEBUG stderr= 2022-12-17T23:53:56Z DEBUG Stop of pki-tomcatd@pki-tomcat.service complete 2022-12-17T23:53:56Z DEBUG step duration: pki-tomcatd stop_instance 0.81 sec 2022-12-17T23:53:56Z DEBUG [3/30]: backing up CS.cfg 2022-12-17T23:53:56Z DEBUG Starting external process 2022-12-17T23:53:56Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:53:56Z DEBUG Process finished, return code=3 2022-12-17T23:53:56Z DEBUG stdout=inactive 2022-12-17T23:53:56Z DEBUG stderr= 2022-12-17T23:53:56Z DEBUG step duration: pki-tomcatd safe_backup_config 0.01 sec 2022-12-17T23:53:56Z DEBUG [4/30]: Add ipa-pki-wait-running 2022-12-17T23:53:56Z DEBUG Starting external process 2022-12-17T23:53:56Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2022-12-17T23:53:56Z DEBUG Process finished, return code=0 2022-12-17T23:53:56Z DEBUG stdout= 2022-12-17T23:53:56Z DEBUG stderr= 2022-12-17T23:53:56Z DEBUG step duration: pki-tomcatd add_ipa_wait 0.37 sec 2022-12-17T23:53:56Z DEBUG [5/30]: secure AJP connector 2022-12-17T23:53:56Z DEBUG Starting external process 2022-12-17T23:53:56Z DEBUG args=['/usr/sbin/tomcat', 'version'] 2022-12-17T23:53:56Z DEBUG Process finished, return code=0 2022-12-17T23:53:56Z DEBUG stdout=Server version: Apache Tomcat/9.0.68 Server built: Nov 3 2033 00:00:00 UTC Server number: 9.0.68.0 OS Name: Linux OS Version: 6.0.12-300.fc37.x86_64 Architecture: amd64 JVM Version: 17.0.5+8 JVM Vendor: Red Hat, Inc. 2022-12-17T23:53:56Z DEBUG stderr=NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.base/java.io=ALL-UNNAMED --add-opens=java.base/java.util=ALL-UNNAMED --add-opens=java.base/java.util.concurrent=ALL-UNNAMED --add-opens=java.rmi/sun.rmi.transport=ALL-UNNAMED 2022-12-17T23:53:56Z DEBUG Starting external process 2022-12-17T23:53:56Z DEBUG args=['/usr/sbin/tomcat', 'version'] 2022-12-17T23:53:56Z DEBUG Process finished, return code=0 2022-12-17T23:53:56Z DEBUG stdout=Server version: Apache Tomcat/9.0.68 Server built: Nov 3 2033 00:00:00 UTC Server number: 9.0.68.0 OS Name: Linux OS Version: 6.0.12-300.fc37.x86_64 Architecture: amd64 JVM Version: 17.0.5+8 JVM Vendor: Red Hat, Inc. 2022-12-17T23:53:56Z DEBUG stderr=NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.base/java.io=ALL-UNNAMED --add-opens=java.base/java.util=ALL-UNNAMED --add-opens=java.base/java.util.concurrent=ALL-UNNAMED --add-opens=java.rmi/sun.rmi.transport=ALL-UNNAMED 2022-12-17T23:53:56Z DEBUG step duration: pki-tomcatd secure_ajp_connector 0.24 sec 2022-12-17T23:53:56Z DEBUG [6/30]: reindex attributes 2022-12-17T23:53:56Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:53:56Z DEBUG Creating ipaca reindex task cn=indextask_ipaca_1671321236,cn=index,cn=tasks,cn=config 2022-12-17T23:53:56Z DEBUG Waiting for task... 2022-12-17T23:53:57Z DEBUG Task cn=indextask_ipaca_1671321236,cn=index,cn=tasks,cn=config has finished with exit code 0 2022-12-17T23:53:57Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:53:57Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:53:57Z DEBUG step duration: pki-tomcatd reindex_task 1.02 sec 2022-12-17T23:53:57Z DEBUG [7/30]: exporting Dogtag certificate store pin 2022-12-17T23:53:57Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:53:57Z DEBUG step duration: pki-tomcatd create_certstore_passwdfile 0.00 sec 2022-12-17T23:53:57Z DEBUG [8/30]: disabling nonces 2022-12-17T23:53:57Z DEBUG step duration: pki-tomcatd __disable_nonce 0.00 sec 2022-12-17T23:53:57Z DEBUG [9/30]: set up CRL publishing 2022-12-17T23:53:57Z DEBUG Starting external process 2022-12-17T23:53:57Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:53:57Z DEBUG Process finished, return code=0 2022-12-17T23:53:57Z DEBUG stdout= 2022-12-17T23:53:57Z DEBUG stderr= 2022-12-17T23:53:57Z DEBUG Starting external process 2022-12-17T23:53:57Z DEBUG args=['/sbin/restorecon', '/var/lib/ipa/pki-ca/publish'] 2022-12-17T23:53:57Z DEBUG Process finished, return code=0 2022-12-17T23:53:57Z DEBUG stdout= 2022-12-17T23:53:57Z DEBUG stderr= 2022-12-17T23:53:57Z DEBUG step duration: pki-tomcatd __enable_crl_publish 0.04 sec 2022-12-17T23:53:57Z DEBUG [10/30]: enable PKIX certificate path discovery and validation 2022-12-17T23:53:57Z DEBUG step duration: pki-tomcatd enable_pkix 0.00 sec 2022-12-17T23:53:57Z DEBUG [11/30]: authorizing RA to modify profiles 2022-12-17T23:53:57Z DEBUG update_entry modlist [(0, 'resourceACLS', [b'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles'])] 2022-12-17T23:53:57Z DEBUG step duration: pki-tomcatd configure_profiles_acl 0.00 sec 2022-12-17T23:53:57Z DEBUG [12/30]: authorizing RA to manage lightweight CAs 2022-12-17T23:53:57Z DEBUG update_entry modlist [(0, 'resourceACLS', [b'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities'])] 2022-12-17T23:53:57Z DEBUG step duration: pki-tomcatd configure_lightweight_ca_acls 0.00 sec 2022-12-17T23:53:57Z DEBUG [13/30]: Ensure lightweight CAs container exists 2022-12-17T23:53:57Z DEBUG step duration: pki-tomcatd ensure_lightweight_cas_container 0.00 sec 2022-12-17T23:53:57Z DEBUG [14/30]: Ensuring backward compatibility 2022-12-17T23:53:57Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:53:57Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:53:57Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:53:57Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:53:57Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:53:57Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:53:57Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:53:57Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:53:57Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:53:58Z DEBUG Created connection context.ldap2_140111960699664 2022-12-17T23:53:58Z DEBUG raw: idrange_show('REDACTED_DOMAIN.COM_id_range', version='2.251') 2022-12-17T23:53:58Z DEBUG idrange_show('REDACTED_DOMAIN.COM_id_range', rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:53:58Z DEBUG flushing ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:53:58Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:53:59Z DEBUG Parsing update file '/usr/share/ipa/updates/50-dogtag10-migration.update' 2022-12-17T23:53:59Z DEBUG Updating existing entry: cn=aclResources,o=ipaca 2022-12-17T23:53:59Z DEBUG --------------------------------------------- 2022-12-17T23:53:59Z DEBUG Initial value 2022-12-17T23:53:59Z DEBUG dn: cn=aclResources,o=ipaca 2022-12-17T23:53:59Z DEBUG resourceACLS: 2022-12-17T23:53:59Z DEBUG certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete 2022-12-17T23:53:59Z DEBUG certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml 2022-12-17T23:53:59Z DEBUG certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter 2022-12-17T23:53:59Z DEBUG certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log 2022-12-17T23:53:59Z DEBUG certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2022-12-17T23:53:59Z DEBUG certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2022-12-17T23:53:59Z DEBUG certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets 2022-12-17T23:53:59Z DEBUG certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory 2022-12-17T23:53:59Z DEBUG certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate 2022-12-17T23:53:59Z DEBUG certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates 2022-12-17T23:53:59Z DEBUG certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests 2022-12-17T23:53:59Z DEBUG certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request 2022-12-17T23:53:59Z DEBUG certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information 2022-12-17T23:53:59Z DEBUG certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests 2022-12-17T23:53:59Z DEBUG certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl 2022-12-17T23:53:59Z DEBUG certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate 2022-12-17T23:53:59Z DEBUG certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates 2022-12-17T23:53:59Z DEBUG certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain 2022-12-17T23:53:59Z DEBUG certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL 2022-12-17T23:53:59Z DEBUG certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request 2022-12-17T23:53:59Z DEBUG certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status 2022-12-17T23:53:59Z DEBUG certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request 2022-12-17T23:53:59Z DEBUG certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate 2022-12-17T23:53:59Z DEBUG certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request 2022-12-17T23:53:59Z DEBUG certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile 2022-12-17T23:53:59Z DEBUG certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles 2022-12-17T23:53:59Z DEBUG certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile 2022-12-17T23:53:59Z DEBUG certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles 2022-12-17T23:53:59Z DEBUG certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles 2022-12-17T23:53:59Z DEBUG certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests 2022-12-17T23:53:59Z DEBUG certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA 2022-12-17T23:53:59Z DEBUG certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics 2022-12-17T23:53:59Z DEBUG certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups 2022-12-17T23:53:59Z DEBUG certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information 2022-12-17T23:53:59Z DEBUG certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent 2022-12-17T23:53:59Z DEBUG certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration. 2022-12-17T23:53:59Z DEBUG certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration. 2022-12-17T23:53:59Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2022-12-17T23:53:59Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2022-12-17T23:53:59Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2022-12-17T23:53:59Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2022-12-17T23:53:59Z DEBUG certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests. 2022-12-17T23:53:59Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2022-12-17T23:53:59Z DEBUG certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities 2022-12-17T23:53:59Z DEBUG certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities 2022-12-17T23:53:59Z DEBUG certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities 2022-12-17T23:53:59Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2022-12-17T23:53:59Z DEBUG certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities 2022-12-17T23:53:59Z DEBUG objectClass: 2022-12-17T23:53:59Z DEBUG top 2022-12-17T23:53:59Z DEBUG CertACLS 2022-12-17T23:53:59Z DEBUG cn: 2022-12-17T23:53:59Z DEBUG aclResources 2022-12-17T23:53:59Z DEBUG addifexist: 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities'] 2022-12-17T23:53:59Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout'] 2022-12-17T23:53:59Z DEBUG addifexist: 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout'] 2022-12-17T23:53:59Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations'] 2022-12-17T23:53:59Z DEBUG addifexist: 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations'] 2022-12-17T23:53:59Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations'] 2022-12-17T23:53:59Z DEBUG addifexist: 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations'] 2022-12-17T23:53:59Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations'] 2022-12-17T23:53:59Z DEBUG addifexist: 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations'] 2022-12-17T23:53:59Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations'] 2022-12-17T23:53:59Z DEBUG replace: certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group":Anybody is allowed to read domain.xml but only Subsystem group is allowed to modify the domain.xml not found, skipping 2022-12-17T23:53:59Z DEBUG replace: updated value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml'] 2022-12-17T23:53:59Z DEBUG replace: certServer.ca.connectorInfo:read,modify:allow (modify,read) group="Enterprise KRA Administrators":Only Enterprise Administrators are allowed to update the connector information not found, skipping 2022-12-17T23:53:59Z DEBUG addifexist: 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml'] 2022-12-17T23:53:59Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles'] 2022-12-17T23:53:59Z DEBUG --------------------------------------------- 2022-12-17T23:53:59Z DEBUG Final value after applying updates 2022-12-17T23:53:59Z DEBUG dn: cn=aclResources,o=ipaca 2022-12-17T23:53:59Z DEBUG resourceACLS: 2022-12-17T23:53:59Z DEBUG certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete 2022-12-17T23:53:59Z DEBUG certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter 2022-12-17T23:53:59Z DEBUG certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log 2022-12-17T23:53:59Z DEBUG certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2022-12-17T23:53:59Z DEBUG certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2022-12-17T23:53:59Z DEBUG certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets 2022-12-17T23:53:59Z DEBUG certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify 2022-12-17T23:53:59Z DEBUG certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory 2022-12-17T23:53:59Z DEBUG certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate 2022-12-17T23:53:59Z DEBUG certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates 2022-12-17T23:53:59Z DEBUG certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests 2022-12-17T23:53:59Z DEBUG certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request 2022-12-17T23:53:59Z DEBUG certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information 2022-12-17T23:53:59Z DEBUG certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests 2022-12-17T23:53:59Z DEBUG certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl 2022-12-17T23:53:59Z DEBUG certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate 2022-12-17T23:53:59Z DEBUG certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates 2022-12-17T23:53:59Z DEBUG certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain 2022-12-17T23:53:59Z DEBUG certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL 2022-12-17T23:53:59Z DEBUG certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request 2022-12-17T23:53:59Z DEBUG certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status 2022-12-17T23:53:59Z DEBUG certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request 2022-12-17T23:53:59Z DEBUG certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate 2022-12-17T23:53:59Z DEBUG certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request 2022-12-17T23:53:59Z DEBUG certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile 2022-12-17T23:53:59Z DEBUG certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles 2022-12-17T23:53:59Z DEBUG certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile 2022-12-17T23:53:59Z DEBUG certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles 2022-12-17T23:53:59Z DEBUG certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles 2022-12-17T23:53:59Z DEBUG certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests 2022-12-17T23:53:59Z DEBUG certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA 2022-12-17T23:53:59Z DEBUG certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics 2022-12-17T23:53:59Z DEBUG certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups 2022-12-17T23:53:59Z DEBUG certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information 2022-12-17T23:53:59Z DEBUG certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent 2022-12-17T23:53:59Z DEBUG certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration. 2022-12-17T23:53:59Z DEBUG certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration. 2022-12-17T23:53:59Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2022-12-17T23:53:59Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2022-12-17T23:53:59Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2022-12-17T23:53:59Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2022-12-17T23:53:59Z DEBUG certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests. 2022-12-17T23:53:59Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2022-12-17T23:53:59Z DEBUG certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities 2022-12-17T23:53:59Z DEBUG certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities 2022-12-17T23:53:59Z DEBUG certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities 2022-12-17T23:53:59Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2022-12-17T23:53:59Z DEBUG certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities 2022-12-17T23:53:59Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2022-12-17T23:53:59Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2022-12-17T23:53:59Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2022-12-17T23:53:59Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2022-12-17T23:53:59Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2022-12-17T23:53:59Z DEBUG certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml 2022-12-17T23:53:59Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2022-12-17T23:53:59Z DEBUG objectClass: 2022-12-17T23:53:59Z DEBUG top 2022-12-17T23:53:59Z DEBUG CertACLS 2022-12-17T23:53:59Z DEBUG cn: 2022-12-17T23:53:59Z DEBUG aclResources 2022-12-17T23:53:59Z DEBUG [(1, 'resourceACLS', ['certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml']), (0, 'resourceACLS', ['certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml'])] 2022-12-17T23:53:59Z DEBUG Updated 1 2022-12-17T23:53:59Z DEBUG update_entry modlist [(1, 'resourceACLS', [b'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml']), (0, 'resourceACLS', [b'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml'])] 2022-12-17T23:53:59Z DEBUG Done 2022-12-17T23:53:59Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-dogtag10-migration.update 0.019 sec 2022-12-17T23:53:59Z DEBUG Destroyed connection context.ldap2_140111960699664 2022-12-17T23:53:59Z DEBUG step duration: pki-tomcatd __dogtag10_migration 1.24 sec 2022-12-17T23:53:59Z DEBUG [15/30]: starting certificate server instance 2022-12-17T23:53:59Z DEBUG Starting external process 2022-12-17T23:53:59Z DEBUG args=['/bin/systemctl', 'start', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:54:11Z DEBUG Process finished, return code=0 2022-12-17T23:54:11Z DEBUG stdout= 2022-12-17T23:54:11Z DEBUG stderr= 2022-12-17T23:54:11Z DEBUG Starting external process 2022-12-17T23:54:11Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:54:11Z DEBUG Process finished, return code=0 2022-12-17T23:54:11Z DEBUG stdout=active 2022-12-17T23:54:11Z DEBUG stderr= 2022-12-17T23:54:11Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 120 2022-12-17T23:54:11Z DEBUG waiting for port: 8080 2022-12-17T23:54:11Z DEBUG SUCCESS: port: 8080 2022-12-17T23:54:11Z DEBUG waiting for port: 8443 2022-12-17T23:54:11Z DEBUG SUCCESS: port: 8443 2022-12-17T23:54:11Z DEBUG Start of pki-tomcatd@pki-tomcat.service complete 2022-12-17T23:54:11Z DEBUG step duration: pki-tomcatd start_instance 11.97 sec 2022-12-17T23:54:11Z DEBUG [16/30]: configure certmonger for renewals 2022-12-17T23:54:11Z DEBUG Starting external process 2022-12-17T23:54:11Z DEBUG args=['/bin/systemctl', 'enable', 'certmonger.service'] 2022-12-17T23:54:11Z DEBUG Process finished, return code=0 2022-12-17T23:54:11Z DEBUG stdout= 2022-12-17T23:54:11Z DEBUG stderr=Created symlink /etc/systemd/system/multi-user.target.wants/certmonger.service → /usr/lib/systemd/system/certmonger.service. 2022-12-17T23:54:11Z DEBUG Starting external process 2022-12-17T23:54:11Z DEBUG args=['/bin/systemctl', 'is-active', 'dbus.service'] 2022-12-17T23:54:11Z DEBUG Process finished, return code=0 2022-12-17T23:54:11Z DEBUG stdout=active 2022-12-17T23:54:11Z DEBUG stderr= 2022-12-17T23:54:11Z DEBUG Starting external process 2022-12-17T23:54:11Z DEBUG args=['/bin/systemctl', 'start', 'certmonger.service'] 2022-12-17T23:54:11Z DEBUG Process finished, return code=0 2022-12-17T23:54:11Z DEBUG stdout= 2022-12-17T23:54:11Z DEBUG stderr= 2022-12-17T23:54:11Z DEBUG Starting external process 2022-12-17T23:54:11Z DEBUG args=['/bin/systemctl', 'is-active', 'certmonger.service'] 2022-12-17T23:54:11Z DEBUG Process finished, return code=0 2022-12-17T23:54:11Z DEBUG stdout=active 2022-12-17T23:54:11Z DEBUG stderr= 2022-12-17T23:54:11Z DEBUG Start of certmonger.service complete 2022-12-17T23:54:11Z DEBUG step duration: pki-tomcatd configure_certmonger_renewal_helpers 0.82 sec 2022-12-17T23:54:11Z DEBUG [17/30]: requesting RA certificate from CA 2022-12-17T23:54:11Z DEBUG Starting external process 2022-12-17T23:54:11Z DEBUG args=['/usr/bin/openssl', 'pkcs7', '-inform', 'DER', '-print_certs', '-out', '/var/lib/ipa/tmpk4al2fho'] 2022-12-17T23:54:11Z DEBUG Process finished, return code=0 2022-12-17T23:54:11Z DEBUG stdout= 2022-12-17T23:54:11Z DEBUG stderr= 2022-12-17T23:54:11Z DEBUG Starting external process 2022-12-17T23:54:11Z DEBUG args=['/usr/bin/openssl', 'pkcs12', '-nokeys', '-clcerts', '-in', '/root/ca-agent.p12', '-out', '/var/lib/ipa/tmpqkgv5mgx', '-passin', 'file:/tmp/tmp8v6uf6vm'] 2022-12-17T23:54:12Z DEBUG Process finished, return code=0 2022-12-17T23:54:12Z DEBUG stdout= 2022-12-17T23:54:12Z DEBUG stderr= 2022-12-17T23:54:12Z DEBUG Starting external process 2022-12-17T23:54:12Z DEBUG args=['/usr/bin/openssl', 'pkcs12', '-nocerts', '-in', '/root/ca-agent.p12', '-out', '/var/lib/ipa/tmpchfm3xz8', '-passin', 'file:/tmp/tmp_8nwt_bo', '-nodes'] 2022-12-17T23:54:12Z DEBUG Process finished, return code=0 2022-12-17T23:54:12Z DEBUG stdout= 2022-12-17T23:54:12Z DEBUG stderr= 2022-12-17T23:54:18Z DEBUG certmonger request is in state 'GENERATING_KEY_PAIR' 2022-12-17T23:54:19Z DEBUG certmonger request is in state 'SUBMITTING' 2022-12-17T23:54:20Z DEBUG certmonger request is in state 'PRE_SAVE_CERT' 2022-12-17T23:54:21Z DEBUG certmonger request is in state 'POST_SAVED_CERT' 2022-12-17T23:54:23Z DEBUG certmonger request is in state 'MONITORING' 2022-12-17T23:54:23Z DEBUG Cert request 20221217235418 was successful 2022-12-17T23:54:23Z DEBUG Starting external process 2022-12-17T23:54:23Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:54:23Z DEBUG Process finished, return code=0 2022-12-17T23:54:23Z DEBUG stdout= 2022-12-17T23:54:23Z DEBUG stderr= 2022-12-17T23:54:23Z DEBUG Starting external process 2022-12-17T23:54:23Z DEBUG args=['/sbin/restorecon', '/var/lib/ipa/ra-agent.pem'] 2022-12-17T23:54:23Z DEBUG Process finished, return code=0 2022-12-17T23:54:23Z DEBUG stdout= 2022-12-17T23:54:23Z DEBUG stderr= 2022-12-17T23:54:23Z DEBUG Starting external process 2022-12-17T23:54:23Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:54:23Z DEBUG Process finished, return code=0 2022-12-17T23:54:23Z DEBUG stdout= 2022-12-17T23:54:23Z DEBUG stderr= 2022-12-17T23:54:23Z DEBUG Starting external process 2022-12-17T23:54:23Z DEBUG args=['/sbin/restorecon', '/var/lib/ipa/ra-agent.key'] 2022-12-17T23:54:23Z DEBUG Process finished, return code=0 2022-12-17T23:54:23Z DEBUG stdout= 2022-12-17T23:54:23Z DEBUG stderr= 2022-12-17T23:54:24Z DEBUG step duration: pki-tomcatd __request_ra_certificate 12.19 sec 2022-12-17T23:54:24Z DEBUG [18/30]: publishing the CA certificate 2022-12-17T23:54:24Z DEBUG step duration: pki-tomcatd __export_ca_chain 0.03 sec 2022-12-17T23:54:24Z DEBUG [19/30]: adding RA agent as a trusted user 2022-12-17T23:54:24Z DEBUG add_entry_to_group: dn=uid=ipara,ou=People,o=ipaca group_dn=cn=Certificate Manager Agents,ou=groups,o=ipaca member_attr=uniqueMember 2022-12-17T23:54:24Z DEBUG add_entry_to_group: dn=uid=ipara,ou=People,o=ipaca group_dn=cn=Registration Manager Agents,ou=groups,o=ipaca member_attr=uniqueMember 2022-12-17T23:54:24Z DEBUG add_entry_to_group: dn=uid=ipara,ou=People,o=ipaca group_dn=cn=Security Domain Administrators,ou=groups,o=ipaca member_attr=uniqueMember 2022-12-17T23:54:24Z DEBUG step duration: pki-tomcatd __create_ca_agent 0.01 sec 2022-12-17T23:54:24Z DEBUG [20/30]: configure certificate renewals 2022-12-17T23:54:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:54:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:54:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:54:28Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:54:29Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:54:31Z DEBUG step duration: pki-tomcatd configure_renewal 7.03 sec 2022-12-17T23:54:31Z DEBUG [21/30]: Configure HTTP to proxy connections 2022-12-17T23:54:31Z DEBUG step duration: pki-tomcatd http_proxy 0.00 sec 2022-12-17T23:54:31Z DEBUG [22/30]: updating IPA configuration 2022-12-17T23:54:31Z DEBUG step duration: pki-tomcatd update_ipa_conf 0.00 sec 2022-12-17T23:54:31Z DEBUG [23/30]: enabling CA instance 2022-12-17T23:54:31Z DEBUG Starting external process 2022-12-17T23:54:31Z DEBUG args=['/bin/systemctl', 'unmask', 'pki-tomcatd.target'] 2022-12-17T23:54:31Z DEBUG Process finished, return code=0 2022-12-17T23:54:31Z DEBUG stdout= 2022-12-17T23:54:31Z DEBUG stderr= 2022-12-17T23:54:31Z DEBUG Starting external process 2022-12-17T23:54:31Z DEBUG args=['/bin/systemctl', 'disable', 'pki-tomcatd.target'] 2022-12-17T23:54:31Z DEBUG Process finished, return code=0 2022-12-17T23:54:31Z DEBUG stdout= 2022-12-17T23:54:31Z DEBUG stderr= 2022-12-17T23:54:31Z DEBUG step duration: pki-tomcatd __enable_instance 0.85 sec 2022-12-17T23:54:31Z DEBUG [24/30]: importing IPA certificate profiles 2022-12-17T23:54:31Z DEBUG request GET https://master.redacted_domain.com:443/ca/rest/account/login 2022-12-17T23:54:31Z DEBUG request body '' 2022-12-17T23:54:31Z DEBUG httplib request failed: Traceback (most recent call last): File "/usr/lib/python3.11/site-packages/ipapython/dogtag.py", line 271, in _httplib_request conn.request(method, path, body=request_body, headers=headers) File "/usr/lib64/python3.11/http/client.py", line 1282, in request self._send_request(method, url, body, headers, encode_chunked) File "/usr/lib64/python3.11/http/client.py", line 1328, in _send_request self.endheaders(body, encode_chunked=encode_chunked) File "/usr/lib64/python3.11/http/client.py", line 1277, in endheaders self._send_output(message_body, encode_chunked=encode_chunked) File "/usr/lib64/python3.11/http/client.py", line 1037, in _send_output self.send(msg) File "/usr/lib64/python3.11/http/client.py", line 975, in send self.connect() File "/usr/lib64/python3.11/http/client.py", line 1447, in connect super().connect() File "/usr/lib64/python3.11/http/client.py", line 941, in connect self.sock = self._create_connection( ^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib64/python3.11/socket.py", line 850, in create_connection raise exceptions[0] File "/usr/lib64/python3.11/socket.py", line 835, in create_connection sock.connect(sa) ConnectionRefusedError: [Errno 111] Connection refused 2022-12-17T23:54:31Z DEBUG Overriding CA port: cannot connect to 'https://master.redacted_domain.com:443/ca/rest/account/login': [Errno 111] Connection refused 2022-12-17T23:54:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:54:31Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:54:31Z DEBUG Trying to find certificate subject base in sysupgrade 2022-12-17T23:54:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:54:31Z DEBUG Found certificate subject base in sysupgrade: O=REDACTED_DOMAIN.COM 2022-12-17T23:54:31Z DEBUG request GET https://master.redacted_domain.com:8443/ca/rest/account/login 2022-12-17T23:54:31Z DEBUG request body '' 2022-12-17T23:54:32Z DEBUG response status 200 2022-12-17T23:54:32Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=6A4784ADF8359738963E0790582B1D5C; Path=/ca; Secure; HttpOnly Content-Type: application/json Content-Length: 165 Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'{"id":"ipara","FullName":"ipara","Roles":["Certificate Manager Agents","Registration Manager Agents","Security Domain Administrators"],"Attributes":{"Attribute":[]}}' 2022-12-17T23:54:32Z DEBUG request POST https://master.redacted_domain.com:8443/ca/rest/profiles/raw 2022-12-17T23:54:32Z DEBUG request body 'profileId=acmeIPAServerCert\nclassId=caEnrollImpl\ndesc=ACME profile for use in IPA deployments\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=SessionAuthentication\nauthz.acl=group="Enterprise ACME Administrators"\nname=IPA ACME Service Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11\npolicyset.serverCertSet.1.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.1.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.1.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.1.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.1.constraint.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.1.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.1.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.1.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.1.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.1.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.1.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.1.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.1.default.name=Key Usage Default\npolicyset.serverCertSet.1.default.params.keyUsageCritical=true\npolicyset.serverCertSet.1.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.1.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.1.default.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.1.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.1.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.1.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.1.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.1.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.1.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.2.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.2.constraint.name=No Constraint\npolicyset.serverCertSet.2.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.2.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.2.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.2.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.3.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.3.constraint.name=No Constraint\npolicyset.serverCertSet.3.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.3.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.3.default.params.critical=false\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.redacted_domain.com/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.6.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.6.default.name=User supplied extension in CSR\npolicyset.serverCertSet.6.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.7.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.7.constraint.name=Validity Constraint\npolicyset.serverCertSet.7.constraint.params.range=90\npolicyset.serverCertSet.7.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.7.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.7.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.7.default.name=Validity Default\npolicyset.serverCertSet.7.default.params.range=90\npolicyset.serverCertSet.7.default.params.startTime=0\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA384withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=sanToCNDefaultImpl\npolicyset.serverCertSet.9.default.name=SAN to CN Default\npolicyset.serverCertSet.10.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.10.constraint.name=Key Constraint\npolicyset.serverCertSet.10.constraint.params.keyType=RSA\npolicyset.serverCertSet.10.constraint.params.keyParameters=2048,3072,4096,8192\npolicyset.serverCertSet.10.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.10.default.name=Key Default\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.11.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.11.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.11.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.11.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.11.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.11.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.11.default.params.crlDistPointsPointName_0=http://ipa-ca.redacted_domain.com/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.11.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.11.default.params.crlDistPointsReasons_0=\n' 2022-12-17T23:54:32Z DEBUG response status 201 2022-12-17T23:54:32Z DEBUG response headers Location: https://master.redacted_domain.com:8443/ca/rest/profiles/raw Content-Type: application/json Content-Length: 6736 Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'#Sun Dec 18 00:54:32 CET 2022\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\ninput.i2.class_id=submitterInfoInputImpl\nauth.instance_id=SessionAuthentication\noutput.o1.class_id=certOutputImpl\npolicyset.serverCertSet.1.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.default.name=SAN to CN Default\npolicyset.serverCertSet.6.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.3.constraint.name=No Constraint\npolicyset.serverCertSet.1.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.params.crlDistPointsPointType_0=URIName\nauthz.acl=group="Enterprise ACME Administrators"\npolicyset.serverCertSet.11.default.params.crlDistPointsNum=1\noutput.list=o1\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.1.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.11.default.name=CRL Distribution Points Extension Default\ninput.list=i1,i2\npolicyset.serverCertSet.11.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.3.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.7.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.1.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.1.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.2.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.1.constraint.params.keyUsageCritical=true\nvisible=true\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.default.name=Key Default\ndesc=ACME profile for use in IPA deployments\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.1.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.1.constraint.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.2.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.2.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.6.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.10.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.2.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.1.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.11.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.7.default.class_id=validityDefaultImpl\nenable=true\npolicyset.serverCertSet.10.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.1.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.10.constraint.params.keyType=RSA\npolicyset.serverCertSet.7.default.params.range=90\npolicyset.serverCertSet.7.default.name=Validity Default\npolicyset.serverCertSet.10.constraint.params.keyParameters=2048,3072,4096,8192\npolicyset.serverCertSet.1.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.1.default.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.7.constraint.params.notAfterCheck=false\ninput.i1.class_id=certReqInputImpl\nenableBy=admin\npolicyset.serverCertSet.7.constraint.name=Validity Constraint\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11\npolicyset.serverCertSet.2.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.1.default.name=Key Usage Default\npolicyset.serverCertSet.6.constraint.name=No Constraint\npolicyset.serverCertSet.1.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.7.constraint.params.range=90\nname=IPA ACME Service Certificate Enrollment\npolicyset.serverCertSet.1.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.3.default.params.critical=false\npolicyset.serverCertSet.11.default.params.crlDistPointsPointName_0=http://ipa-ca.redacted_domain.com/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.1.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.11.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.2.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.11.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.6.default.name=User supplied extension in CSR\npolicyset.serverCertSet.1.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.1.default.params.keyUsageCritical=true\npolicyset.serverCertSet.9.default.class_id=sanToCNDefaultImpl\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA384withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.1.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.3.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.7.constraint.class_id=validityConstraintImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.1.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.1.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.3.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.default.params.startTime=0\npolicyset.serverCertSet.1.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.constraint.name=Key Constraint\npolicyset.serverCertSet.1.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.redacted_domain.com/ca/ocsp\npolicyset.serverCertSet.6.default.params.userExtOID=2.5.29.17\n' 2022-12-17T23:54:32Z DEBUG Profile 'acmeIPAServerCert' successfully migrated to LDAP 2022-12-17T23:54:32Z DEBUG request POST https://master.redacted_domain.com:8443/ca/rest/profiles/acmeIPAServerCert?action=enable 2022-12-17T23:54:32Z DEBUG request body '' 2022-12-17T23:54:32Z DEBUG response status 204 2022-12-17T23:54:32Z DEBUG response headers Content-Type: application/json Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'' 2022-12-17T23:54:32Z DEBUG request GET https://master.redacted_domain.com:8443/ca/rest/account/logout 2022-12-17T23:54:32Z DEBUG request body '' 2022-12-17T23:54:32Z DEBUG response status 204 2022-12-17T23:54:32Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=6E8E22C2F0152C248A266F38DD1BFCD4; Path=/ca; Secure; HttpOnly Content-Type: application/json Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'' 2022-12-17T23:54:32Z DEBUG Imported profile 'acmeIPAServerCert' 2022-12-17T23:54:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:54:32Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:54:32Z DEBUG Trying to find certificate subject base in sysupgrade 2022-12-17T23:54:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:54:32Z DEBUG Found certificate subject base in sysupgrade: O=REDACTED_DOMAIN.COM 2022-12-17T23:54:32Z DEBUG request GET https://master.redacted_domain.com:8443/ca/rest/account/login 2022-12-17T23:54:32Z DEBUG request body '' 2022-12-17T23:54:32Z DEBUG response status 200 2022-12-17T23:54:32Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=B1D83FD502D5190141BB4B58DC7452D7; Path=/ca; Secure; HttpOnly Content-Type: application/json Content-Length: 165 Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'{"id":"ipara","FullName":"ipara","Roles":["Certificate Manager Agents","Registration Manager Agents","Security Domain Administrators"],"Attributes":{"Attribute":[]}}' 2022-12-17T23:54:32Z DEBUG request POST https://master.redacted_domain.com:8443/ca/rest/profiles/raw 2022-12-17T23:54:32Z DEBUG request body 'profileId=caIPAserviceCert\nclassId=caEnrollImpl\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=REDACTED_DOMAIN.COM\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,8192\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.redacted_domain.com/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.redacted_domain.com/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name\n' 2022-12-17T23:54:32Z DEBUG response status 409 2022-12-17T23:54:32Z DEBUG response headers Content-Type: application/json Content-Length: 173 Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Unable to create profile: Profile already exists"}' 2022-12-17T23:54:32Z DEBUG Error migrating 'caIPAserviceCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Unable to create profile: Profile already exists 2022-12-17T23:54:32Z DEBUG request POST https://master.redacted_domain.com:8443/ca/rest/profiles/caIPAserviceCert?action=disable 2022-12-17T23:54:32Z DEBUG request body '' 2022-12-17T23:54:32Z DEBUG response status 204 2022-12-17T23:54:32Z DEBUG response headers Content-Type: application/json Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'' 2022-12-17T23:54:32Z DEBUG request PUT https://master.redacted_domain.com:8443/ca/rest/profiles/caIPAserviceCert/raw 2022-12-17T23:54:32Z DEBUG request body 'profileId=caIPAserviceCert\nclassId=caEnrollImpl\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=REDACTED_DOMAIN.COM\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,8192\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.redacted_domain.com/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.redacted_domain.com/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name\n' 2022-12-17T23:54:32Z DEBUG response status 200 2022-12-17T23:54:32Z DEBUG response headers Cache-Control: private Content-Type: application/json Content-Length: 7313 Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'#Sun Dec 18 00:54:32 CET 2022\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.2.default.params.range=731\ninput.i2.class_id=submitterInfoInputImpl\nauth.instance_id=raCertAuth\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\noutput.o1.class_id=certOutputImpl\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\noutput.list=o1\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\ninput.list=i1,i2\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\nvisible=false\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.redacted_domain.com/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\nenable=true\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,8192\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\ninput.i1.class_id=certReqInputImpl\nenableBy=admin\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=REDACTED_DOMAIN.COM\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.redacted_domain.com/ca/ocsp\n' 2022-12-17T23:54:32Z DEBUG request POST https://master.redacted_domain.com:8443/ca/rest/profiles/caIPAserviceCert?action=enable 2022-12-17T23:54:32Z DEBUG request body '' 2022-12-17T23:54:32Z DEBUG response status 204 2022-12-17T23:54:32Z DEBUG response headers Content-Type: application/json Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'' 2022-12-17T23:54:32Z DEBUG request GET https://master.redacted_domain.com:8443/ca/rest/account/logout 2022-12-17T23:54:32Z DEBUG request body '' 2022-12-17T23:54:32Z DEBUG response status 204 2022-12-17T23:54:32Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=12E0D4253AE3405FF150300795285E46; Path=/ca; Secure; HttpOnly Content-Type: application/json Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'' 2022-12-17T23:54:32Z DEBUG Imported profile 'caIPAserviceCert' 2022-12-17T23:54:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:54:32Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:54:32Z DEBUG Trying to find certificate subject base in sysupgrade 2022-12-17T23:54:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:54:32Z DEBUG Found certificate subject base in sysupgrade: O=REDACTED_DOMAIN.COM 2022-12-17T23:54:32Z DEBUG request GET https://master.redacted_domain.com:8443/ca/rest/account/login 2022-12-17T23:54:32Z DEBUG request body '' 2022-12-17T23:54:32Z DEBUG response status 200 2022-12-17T23:54:32Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=1C3E83D34148B09FC77E933B523FF7E1; Path=/ca; Secure; HttpOnly Content-Type: application/json Content-Length: 165 Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'{"id":"ipara","FullName":"ipara","Roles":["Certificate Manager Agents","Registration Manager Agents","Security Domain Administrators"],"Attributes":{"Attribute":[]}}' 2022-12-17T23:54:32Z DEBUG request POST https://master.redacted_domain.com:8443/ca/rest/profiles/raw 2022-12-17T23:54:32Z DEBUG request body 'profileId=KDCs_PKINIT_Certs\nclassId=caEnrollImpl\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=REDACTED_DOMAIN.COM\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.redacted_domain.com/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.2.3.5\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.redacted_domain.com/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name\n' 2022-12-17T23:54:32Z DEBUG response status 201 2022-12-17T23:54:32Z DEBUG response headers Location: https://master.redacted_domain.com:8443/ca/rest/profiles/raw Content-Type: application/json Content-Length: 7279 Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'#Sun Dec 18 00:54:32 CET 2022\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.2.3.5\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.2.default.params.range=731\ninput.i2.class_id=submitterInfoInputImpl\nauth.instance_id=raCertAuth\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\noutput.o1.class_id=certOutputImpl\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\noutput.list=o1\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\ninput.list=i1,i2\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\nvisible=false\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.redacted_domain.com/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\nenable=true\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.3.constraint.params.keyParameters=2048,3072,4096\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\ninput.i1.class_id=certReqInputImpl\nenableBy=admin\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=REDACTED_DOMAIN.COM\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.redacted_domain.com/ca/ocsp\n' 2022-12-17T23:54:32Z DEBUG Profile 'KDCs_PKINIT_Certs' successfully migrated to LDAP 2022-12-17T23:54:32Z DEBUG request POST https://master.redacted_domain.com:8443/ca/rest/profiles/KDCs_PKINIT_Certs?action=enable 2022-12-17T23:54:32Z DEBUG request body '' 2022-12-17T23:54:32Z DEBUG response status 204 2022-12-17T23:54:32Z DEBUG response headers Content-Type: application/json Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'' 2022-12-17T23:54:32Z DEBUG request GET https://master.redacted_domain.com:8443/ca/rest/account/logout 2022-12-17T23:54:32Z DEBUG request body '' 2022-12-17T23:54:32Z DEBUG response status 204 2022-12-17T23:54:32Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=4686BA71F8C4CDE427DC366D1D821C22; Path=/ca; Secure; HttpOnly Content-Type: application/json Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'' 2022-12-17T23:54:32Z DEBUG Imported profile 'KDCs_PKINIT_Certs' 2022-12-17T23:54:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:54:32Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:54:32Z DEBUG Trying to find certificate subject base in sysupgrade 2022-12-17T23:54:32Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:54:32Z DEBUG Found certificate subject base in sysupgrade: O=REDACTED_DOMAIN.COM 2022-12-17T23:54:32Z DEBUG request GET https://master.redacted_domain.com:8443/ca/rest/account/login 2022-12-17T23:54:32Z DEBUG request body '' 2022-12-17T23:54:32Z DEBUG response status 200 2022-12-17T23:54:32Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=22CF8CE6B19CB1A4A570C501EC223B63; Path=/ca; Secure; HttpOnly Content-Type: application/json Content-Length: 165 Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'{"id":"ipara","FullName":"ipara","Roles":["Certificate Manager Agents","Registration Manager Agents","Security Domain Administrators"],"Attributes":{"Attribute":[]}}' 2022-12-17T23:54:32Z DEBUG request POST https://master.redacted_domain.com:8443/ca/rest/profiles/raw 2022-12-17T23:54:32Z DEBUG request body 'profileId=IECUserRoles\nclassId=caEnrollImpl\ndesc=Enroll user certificates with IECUserRoles extension via IPA-RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=REDACTED_DOMAIN.COM\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.redacted_domain.com/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.redacted_domain.com/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.12.default.name=IECUserRoles Extension Default\npolicyset.serverCertSet.12.default.params.userExtOID=1.2.840.10070.8.1\n' 2022-12-17T23:54:32Z DEBUG response status 201 2022-12-17T23:54:32Z DEBUG response headers Location: https://master.redacted_domain.com:8443/ca/rest/profiles/raw Content-Type: application/json Content-Length: 7353 Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'#Sun Dec 18 00:54:32 CET 2022\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.2.default.params.range=731\ninput.i2.class_id=submitterInfoInputImpl\nauth.instance_id=raCertAuth\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\noutput.o1.class_id=certOutputImpl\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\noutput.list=o1\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\ninput.list=i1,i2\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\nvisible=false\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\ndesc=Enroll user certificates with IECUserRoles extension via IPA-RA agent authentication.\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.redacted_domain.com/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\nenable=true\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\ninput.i1.class_id=certReqInputImpl\nenableBy=admin\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=REDACTED_DOMAIN.COM\npolicyset.serverCertSet.12.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.12.default.params.userExtOID=1.2.840.10070.8.1\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.12.default.name=IECUserRoles Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.redacted_domain.com/ca/ocsp\n' 2022-12-17T23:54:32Z DEBUG Profile 'IECUserRoles' successfully migrated to LDAP 2022-12-17T23:54:32Z DEBUG request POST https://master.redacted_domain.com:8443/ca/rest/profiles/IECUserRoles?action=enable 2022-12-17T23:54:32Z DEBUG request body '' 2022-12-17T23:54:32Z DEBUG response status 204 2022-12-17T23:54:32Z DEBUG response headers Content-Type: application/json Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'' 2022-12-17T23:54:32Z DEBUG request GET https://master.redacted_domain.com:8443/ca/rest/account/logout 2022-12-17T23:54:32Z DEBUG request body '' 2022-12-17T23:54:32Z DEBUG response status 204 2022-12-17T23:54:32Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=6FBEE98AB39A68D35EAC75D78D229D04; Path=/ca; Secure; HttpOnly Content-Type: application/json Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:32Z DEBUG response body (decoded): b'' 2022-12-17T23:54:32Z DEBUG Imported profile 'IECUserRoles' 2022-12-17T23:54:32Z DEBUG step duration: pki-tomcatd import_included_profiles 1.03 sec 2022-12-17T23:54:32Z DEBUG [25/30]: migrating certificate profiles to LDAP 2022-12-17T23:54:33Z DEBUG Profile 'acmeServerCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCMCserverCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCMCECserverCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCMCECsubsystemCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCMCsubsystemCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCMCauditSigningCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCMCcaCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCMCocspCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCMCkraTransportCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCMCkraStorageCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caServerKeygen_UserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caServerKeygen_DirUserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caUserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caECUserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caUserSMIMEcapCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caDualCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caDirBasedDualCert' is already in LDAP and disabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'AdminCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'ECAdminCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caSignedLogCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caTPSCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caRARouterCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caRouterCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caServerCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caECServerCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caServerCertWithSCT' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caECServerCertWithSCT' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caSubsystemCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caECSubsystemCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caOtherCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCACert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCMCcaCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCrossSignedCACert' is already in LDAP and disabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caInstallCACert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caRACert' is already in LDAP and disabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caOCSPCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caStorageCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caTransportCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caDirPinUserCert' is already in LDAP and disabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caECDirPinUserCert' is already in LDAP and disabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caDirUserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caECDirUserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caAgentServerCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caECAgentServerCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caAgentFileSigning' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCMCUserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCMCECUserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caCMCcaIssuanceProtectionCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caFullCMCUserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caECFullCMCUserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caFullCMCUserSignedCert' is already in LDAP and disabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caECFullCMCUserSignedCert' is already in LDAP and disabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caFullCMCSharedTokenCert' is already in LDAP and disabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caECFullCMCSharedTokenCert' is already in LDAP and disabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caSimpleCMCUserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caECSimpleCMCUserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caTokenDeviceKeyEnrollment' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caTokenUserEncryptionKeyEnrollment' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caTokenUserSigningKeyEnrollment' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caTempTokenDeviceKeyEnrollment' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caTempTokenUserEncryptionKeyEnrollment' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caTempTokenUserSigningKeyEnrollment' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caAdminCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caECAdminCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caInternalAuthServerCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caECInternalAuthServerCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caInternalAuthTransportCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caInternalAuthDRMstorageCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caInternalAuthSubsystemCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caECInternalAuthSubsystemCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caInternalAuthOCSPCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caInternalAuthAuditSigningCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'DomainController' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caDualRAuserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caRAagentCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caRAserverCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caUUIDdeviceCert' is already in LDAP and disabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caSSLClientSelfRenewal' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caDirUserRenewal' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caManualRenewal' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caTokenMSLoginEnrollment' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caTokenUserSigningKeyRenewal' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caTokenUserEncryptionKeyRenewal' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caTokenUserAuthKeyRenewal' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caJarSigningCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caIPAserviceCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caAuditSigningCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caEncUserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caSigningUserCert' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caTokenUserDelegateAuthKeyEnrollment' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG Profile 'caTokenUserDelegateSigningKeyEnrollment' is already in LDAP and enabled; skipping 2022-12-17T23:54:33Z DEBUG step duration: pki-tomcatd migrate_profiles_to_ldap 0.03 sec 2022-12-17T23:54:33Z DEBUG [26/30]: adding default CA ACL 2022-12-17T23:54:33Z DEBUG raw: caacl_find(None, version='2.251') 2022-12-17T23:54:33Z DEBUG caacl_find(None, all=False, raw=False, version='2.251', no_members=True, pkey_only=False) 2022-12-17T23:54:33Z DEBUG raw: caacl_add('hosts_services_caIPAserviceCert', hostcategory='all', servicecategory='all', version='2.251') 2022-12-17T23:54:33Z DEBUG caacl_add('hosts_services_caIPAserviceCert', hostcategory='all', servicecategory='all', all=False, raw=False, version='2.251', no_members=False) 2022-12-17T23:54:33Z DEBUG raw: caacl_add_profile('hosts_services_caIPAserviceCert', version='2.251', certprofile=('caIPAserviceCert',)) 2022-12-17T23:54:33Z DEBUG caacl_add_profile('hosts_services_caIPAserviceCert', all=False, raw=False, version='2.251', no_members=False, certprofile=('caIPAserviceCert',)) 2022-12-17T23:54:33Z DEBUG add_entry_to_group: dn=cn=caIPAserviceCert,cn=certprofiles,cn=ca,dc=redacted_domain,dc=com group_dn=ipaUniqueID=2758855e-7e66-11ed-b18f-525400000010,cn=caacls,cn=ca,dc=redacted_domain,dc=com member_attr=ipamembercertprofile 2022-12-17T23:54:33Z DEBUG step duration: pki-tomcatd ensure_default_caacl 0.03 sec 2022-12-17T23:54:33Z DEBUG [27/30]: adding 'ipa' CA entry 2022-12-17T23:54:33Z DEBUG request GET https://master.redacted_domain.com:8443/ca/rest/account/login 2022-12-17T23:54:33Z DEBUG request body '' 2022-12-17T23:54:33Z DEBUG response status 200 2022-12-17T23:54:33Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=C019C8C5889C9105DF62EF6EB03AA6E4; Path=/ca; Secure; HttpOnly Content-Type: application/json Content-Length: 165 Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:33Z DEBUG response body (decoded): b'{"id":"ipara","FullName":"ipara","Roles":["Certificate Manager Agents","Registration Manager Agents","Security Domain Administrators"],"Attributes":{"Attribute":[]}}' 2022-12-17T23:54:33Z DEBUG request GET https://master.redacted_domain.com:8443/ca/rest/authorities/host-authority 2022-12-17T23:54:33Z DEBUG request body '' 2022-12-17T23:54:33Z DEBUG response status 200 2022-12-17T23:54:33Z DEBUG response headers Cache-Control: private Content-Type: application/json Content-Length: 244 Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:33Z DEBUG response body (decoded): b'{"isHostAuthority":true,"id":"bc15c9ed-13bc-422a-8af0-8e5e72ea7d26","issuerDN":"CN=Certificate Authority,O=REDACTED_DOMAIN.COM","serial":1,"dn":"CN=Certificate Authority,O=REDACTED_DOMAIN.COM","enabled":true,"description":"Host authority","ready":true}' 2022-12-17T23:54:33Z DEBUG request GET https://master.redacted_domain.com:8443/ca/rest/account/logout 2022-12-17T23:54:33Z DEBUG request body '' 2022-12-17T23:54:33Z DEBUG response status 204 2022-12-17T23:54:33Z DEBUG response headers Cache-Control: private Set-Cookie: JSESSIONID=540AFBFA4FEC470E4F28E02E7B5652D8; Path=/ca; Secure; HttpOnly Content-Type: application/json Date: Sat, 17 Dec 2022 23:54:32 GMT 2022-12-17T23:54:33Z DEBUG response body (decoded): b'' 2022-12-17T23:54:33Z DEBUG step duration: pki-tomcatd ensure_ipa_authority_entry 0.13 sec 2022-12-17T23:54:33Z DEBUG [28/30]: Recording random serial number state 2022-12-17T23:54:33Z DEBUG update_entry modlist [(2, 'ipaCaRandomSerialNumberVersion', [b'0'])] 2022-12-17T23:54:33Z DEBUG step duration: pki-tomcatd __store_random_serial_number_state 0.00 sec 2022-12-17T23:54:33Z DEBUG [29/30]: configuring certmonger renewal for lightweight CAs 2022-12-17T23:54:33Z DEBUG step duration: pki-tomcatd add_lightweight_ca_tracking_requests 0.00 sec 2022-12-17T23:54:33Z DEBUG [30/30]: deploying ACME service 2022-12-17T23:54:33Z DEBUG Deploying ACME 2022-12-17T23:54:33Z DEBUG Starting external process 2022-12-17T23:54:33Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/pki/acme/database/ds/schema.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:54:33Z DEBUG Process finished, return code=0 2022-12-17T23:54:33Z DEBUG stdout=add attributeTypes: ( acmeCreated-oid NAME 'acmeCreated' SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 EQUALITY generalizedTimeMatch ORDERING generalizedTimeOrderingMatch SINGLE-VALUE ) ( acmeExpires-oid NAME 'acmeExpires' SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 EQUALITY generalizedTimeMatch ORDERING generalizedTimeOrderingMatch SINGLE-VALUE ) ( acmeValidatedAt-oid NAME 'acmeValidatedAt' SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 EQUALITY generalizedTimeMatch ORDERING generalizedTimeOrderingMatch SINGLE-VALUE ) ( acmeStatus-oid NAME 'acmeStatus' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 EQUALITY caseIgnoreMatch SINGLE-VALUE ) ( acmeError-oid NAME 'acmeError' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE ) ( acmeNonceId-oid NAME 'acmeNonceId' SUP name SINGLE-VALUE ) ( acmeAccountId-oid NAME 'acmeAccountId' SUP name SINGLE-VALUE ) ( acmeAccountContact-oid NAME 'acmeAccountContact' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 EQUALITY caseIgnoreMatch SUBSTR caseIgnoreSubstringsMatch ) ( acmeAccountKey-oid NAME 'acmeAccountKey' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE ) ( acmeOrderId-oid NAME 'acmeOrderId' SUP name SINGLE-VALUE ) ( acmeIdentifier-oid NAME 'acmeIdentifier' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 EQUALITY caseIgnoreMatch ) ( acmeAuthorizationId-oid NAME 'acmeAuthorizationId' SUP name ) ( acmeAuthorizationWildcard-oid NAME 'acmeAuthorizationWildcard' SYNTAX 1.3.6.1.4.1.1466.115.121.1.7 EQUALITY booleanMatch SINGLE-VALUE ) ( acmeChallengeId-oid NAME 'acmeChallengeId' SUP name SINGLE-VALUE ) ( acmeToken-oid NAME 'acmeToken' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) ( acmeCertificateId-oid NAME 'acmeCertificateId' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 EQUALITY caseExactMatch SINGLE-VALUE ) ( acmeEnabled-oid NAME 'acmeEnabled' SYNTAX 1.3.6.1.4.1.1466.115.121.1.7 EQUALITY booleanMatch SINGLE-VALUE ) add objectClasses: ( acmeNonce-oid NAME 'acmeNonce' STRUCTURAL MUST ( acmeNonceId $ acmeCreated $ acmeExpires ) ) ( acmeAccount-oid NAME 'acmeAccount' STRUCTURAL MUST ( acmeAccountId $ acmeCreated $ acmeAccountKey $ acmeStatus ) MAY acmeAccountContact ) ( acmeOrder-oid NAME 'acmeOrder' STRUCTURAL MUST ( acmeOrderId $ acmeAccountId $ acmeCreated $ acmeStatus $ acmeIdentifier $ acmeAuthorizationId ) MAY ( acmeError $ acmeCertificateId $ acmeExpires ) ) ( acmeAuthorization-oid NAME 'acmeAuthorization' STRUCTURAL MUST ( acmeAuthorizationId $ acmeAccountId $ acmeCreated $ acmeIdentifier $ acmeAuthorizationWildcard $ acmeStatus ) MAY acmeExpires ) ( acmeChallenge-oid NAME 'acmeChallenge' ABSTRACT MUST ( acmeChallengeId $ acmeAccountId $ acmeAuthorizationId $ acmeStatus ) MAY ( acmeValidatedAt $ acmeError ) ) ( acmeChallengeDns01-oid NAME 'acmeChallengeDns01' SUP acmeChallenge STRUCTURAL MUST acmeToken ) ( acmeChallengeHttp01-oid NAME 'acmeChallengeHttp01' SUP acmeChallenge STRUCTURAL MUST acmeToken ) ( acmeCertificate-oid NAME 'acmeCertificate' STRUCTURAL MUST ( acmeCertificateId $ acmeCreated $ userCertificate ) MAY acmeExpires ) modifying entry "cn=schema" modify complete 2022-12-17T23:54:33Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:54:33Z DEBUG update_entry modlist [(0, 'resourceACLS', [b'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations'])] 2022-12-17T23:54:33Z DEBUG add_entry_to_group: dn=uid=ipara,ou=People,o=ipaca group_dn=cn=Enterprise ACME Administrators,ou=groups,o=ipaca member_attr=uniqueMember 2022-12-17T23:54:33Z DEBUG Starting external process 2022-12-17T23:54:33Z DEBUG args=['pki-server', 'acme-create'] 2022-12-17T23:54:33Z DEBUG Process finished, return code=0 2022-12-17T23:54:33Z DEBUG stdout= 2022-12-17T23:54:33Z DEBUG stderr= 2022-12-17T23:54:33Z DEBUG Starting external process 2022-12-17T23:54:33Z DEBUG args=['pki-server', 'acme-deploy'] 2022-12-17T23:54:34Z DEBUG Process finished, return code=0 2022-12-17T23:54:34Z DEBUG stdout= 2022-12-17T23:54:34Z DEBUG stderr= 2022-12-17T23:54:34Z DEBUG step duration: pki-tomcatd setup_acme 0.94 sec 2022-12-17T23:54:34Z DEBUG Done configuring certificate server (pki-tomcatd). 2022-12-17T23:54:34Z DEBUG service duration: pki-tomcatd 182.81 sec 2022-12-17T23:54:34Z DEBUG Removing /root/.dogtag/pki-tomcat/ca 2022-12-17T23:54:34Z DEBUG Configuring directory server (dirsrv) 2022-12-17T23:54:34Z DEBUG [1/3]: configuring TLS for DS instance 2022-12-17T23:54:34Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:54:34Z DEBUG Starting external process 2022-12-17T23:54:34Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/', '-L', '-n', 'REDACTED_DOMAIN.COM IPA CA', '-a', '-f', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/pwdfile.txt'] 2022-12-17T23:54:34Z DEBUG Process finished, return code=255 2022-12-17T23:54:34Z DEBUG stdout= 2022-12-17T23:54:34Z DEBUG stderr=certutil: Could not find cert: REDACTED_DOMAIN.COM IPA CA : PR_FILE_NOT_FOUND_ERROR: File not found 2022-12-17T23:54:34Z DEBUG Starting external process 2022-12-17T23:54:34Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/', '-N', '-f', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/pwdfile.txt', '-@', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/pwdfile.txt'] 2022-12-17T23:54:34Z DEBUG Process finished, return code=0 2022-12-17T23:54:34Z DEBUG stdout= 2022-12-17T23:54:34Z DEBUG stderr= 2022-12-17T23:54:34Z DEBUG Starting external process 2022-12-17T23:54:34Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:54:34Z DEBUG Process finished, return code=0 2022-12-17T23:54:34Z DEBUG stdout= 2022-12-17T23:54:34Z DEBUG stderr= 2022-12-17T23:54:34Z DEBUG Starting external process 2022-12-17T23:54:34Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/'] 2022-12-17T23:54:34Z DEBUG Process finished, return code=0 2022-12-17T23:54:34Z DEBUG stdout= 2022-12-17T23:54:34Z DEBUG stderr= 2022-12-17T23:54:34Z DEBUG Starting external process 2022-12-17T23:54:34Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:54:34Z DEBUG Process finished, return code=0 2022-12-17T23:54:34Z DEBUG stdout= 2022-12-17T23:54:34Z DEBUG stderr= 2022-12-17T23:54:34Z DEBUG Starting external process 2022-12-17T23:54:34Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/cert9.db'] 2022-12-17T23:54:34Z DEBUG Process finished, return code=0 2022-12-17T23:54:34Z DEBUG stdout= 2022-12-17T23:54:34Z DEBUG stderr= 2022-12-17T23:54:34Z DEBUG Starting external process 2022-12-17T23:54:34Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:54:34Z DEBUG Process finished, return code=0 2022-12-17T23:54:34Z DEBUG stdout= 2022-12-17T23:54:34Z DEBUG stderr= 2022-12-17T23:54:34Z DEBUG Starting external process 2022-12-17T23:54:34Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/key4.db'] 2022-12-17T23:54:34Z DEBUG Process finished, return code=0 2022-12-17T23:54:34Z DEBUG stdout= 2022-12-17T23:54:34Z DEBUG stderr= 2022-12-17T23:54:34Z DEBUG Starting external process 2022-12-17T23:54:34Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:54:34Z DEBUG Process finished, return code=0 2022-12-17T23:54:34Z DEBUG stdout= 2022-12-17T23:54:34Z DEBUG stderr= 2022-12-17T23:54:34Z DEBUG Starting external process 2022-12-17T23:54:34Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/pkcs11.txt'] 2022-12-17T23:54:34Z DEBUG Process finished, return code=0 2022-12-17T23:54:34Z DEBUG stdout= 2022-12-17T23:54:34Z DEBUG stderr= 2022-12-17T23:54:34Z DEBUG Starting external process 2022-12-17T23:54:34Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:54:34Z DEBUG Process finished, return code=0 2022-12-17T23:54:34Z DEBUG stdout= 2022-12-17T23:54:34Z DEBUG stderr= 2022-12-17T23:54:34Z DEBUG Starting external process 2022-12-17T23:54:34Z DEBUG args=['/sbin/restorecon', '-F', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/pwdfile.txt'] 2022-12-17T23:54:34Z DEBUG Process finished, return code=0 2022-12-17T23:54:34Z DEBUG stdout= 2022-12-17T23:54:34Z DEBUG stderr= 2022-12-17T23:54:34Z DEBUG Starting external process 2022-12-17T23:54:34Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/', '-A', '-n', 'REDACTED_DOMAIN.COM IPA CA', '-t', 'CT,C,C', '-a', '-f', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/pwdfile.txt'] 2022-12-17T23:54:34Z DEBUG Process finished, return code=0 2022-12-17T23:54:34Z DEBUG stdout= 2022-12-17T23:54:34Z DEBUG stderr= 2022-12-17T23:54:35Z DEBUG certmonger request is in state 'NEWLY_ADDED_READING_KEYINFO' 2022-12-17T23:54:35Z DEBUG certmonger request is in state 'GENERATING_KEY_PAIR' 2022-12-17T23:54:36Z DEBUG certmonger request is in state 'READING_KEYINFO' 2022-12-17T23:54:37Z DEBUG certmonger request is in state 'GENERATING_CSR' 2022-12-17T23:54:37Z DEBUG certmonger request is in state 'SUBMITTING' 2022-12-17T23:54:38Z DEBUG certmonger request is in state 'READING_CERT' 2022-12-17T23:54:38Z DEBUG certmonger request is in state 'POST_SAVED_CERT' 2022-12-17T23:54:44Z DEBUG certmonger request is in state 'MONITORING' 2022-12-17T23:54:44Z DEBUG Cert request 20221217235434 was successful 2022-12-17T23:54:45Z DEBUG Destroyed connection context.ldap2_140111978781200 2022-12-17T23:54:45Z DEBUG Created connection context.ldap2_140111978781200 2022-12-17T23:54:45Z DEBUG Starting external process 2022-12-17T23:54:45Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/', '-L', '-n', 'Server-Cert', '-a', '-f', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/pwdfile.txt'] 2022-12-17T23:54:45Z DEBUG Process finished, return code=0 2022-12-17T23:54:45Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIFWzCCA8OgAwIBAgIBCDANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05J VkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0y MjEyMTcyMzU0MzdaFw0yNDEyMTcyMzU0MzdaMD0xGDAWBgNVBAoMD01PTklWQUdS T1VQLkNPTTEhMB8GA1UEAwwYbWlkbTAwMXAubW9uaXZhZ3JvdXAuY29tMIIBIjAN BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxH39gdMf9r8GSSGOAnK+VtKj05cF jwoyg4x/PFSgv+txbYqvT155te7vmC56bZaZlmf2AwGb/TxI6YS12I/RlbjHQGR0 RjWTYfP5Y6bG/mjJ39CPspGQuv0oJxUYi+uNczB7lbY4zekZiphvYhi7LuqsrYjn 3VE0zdjfFQqxjhZ+PsBJfWo89o4MLsa/0us8zzX5wjzdGmsCWzUQ6xUoiaco6QPE +7BcBL0Cr6hZ2vaczlKc5uu24weFydoX6v4Xa9Ku5vMF5urzAeSEBqjxn5QRQdJI I9p3r65zJi9wqkGdlrlYh1vZU0uNfH6an59X3qQagVDBJkFy8oRdi79vhwIDAQAB o4IB5zCCAeMwHwYDVR0jBBgwFoAUnCHM6adwr08G/ZX+WF9+wfZnocYwQQYIKwYB BQUHAQEENTAzMDEGCCsGAQUFBzABhiVodHRwOi8vaXBhLWNhLm1vbml2YWdyb3Vw LmNvbS9jYS9vY3NwMA4GA1UdDwEB/wQEAwIE8DAdBgNVHSUEFjAUBggrBgEFBQcD AQYIKwYBBQUHAwIwegYDVR0fBHMwcTBvoDegNYYzaHR0cDovL2lwYS1jYS5tb25p dmFncm91cC5jb20vaXBhL2NybC9NYXN0ZXJDUkwuYmluojSkMjAwMQ4wDAYDVQQK DAVpcGFjYTEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB0GA1UdDgQW BBQ16FDxPHS5fXkEyBz87DSCidgpnjCBsgYDVR0RBIGqMIGnghhtaWRtMDAxcC5t b25pdmFncm91cC5jb22gPQYKKwYBBAGCNxQCA6AvDC1sZGFwL21pZG0wMDFwLm1v bml2YWdyb3VwLmNvbUBNT05JVkFHUk9VUC5DT02gTAYGKwYBBQICoEIwQKARGw9N T05JVkFHUk9VUC5DT02hKzApoAMCAQGhIjAgGwRsZGFwGxhtaWRtMDAxcC5tb25p dmFncm91cC5jb20wDQYJKoZIhvcNAQENBQADggGBAFz+uWD9m2hLcYH7X45RpL0Y 67hfyJveFRxTXeSBnmDCRUcSzl/p/npP8Ss9lXlJWhA/Rd4bK9LJQ6HtVx6qm4wV jFxJfdh57y+uMK9ZNPuZu/bn11o8bAjY7hRNikOkQL75NiEHQJfkm2T8G45BgpfN ZQgeZKTe2Tp63zCbsGSvQDadisThy8WVa9bgKowK+76UoxKa3YtTWG5ghc7++LKe lIF+r6WaKC+d2ARxzPv1n+R746UuZItN2U5Y9S729QSs2804XYvEMaUaumbdtPAY Pom3+ZFf11shW8cUzFmPoATeMKqbLpDSXim6qKxc5zJmePzgOcNIpVRaGWY6skkf WGe7CMfpm0kHG6A1kwNNj2wBGQ3/NSIEeHD+mRaEXLDPo6d+3P14ANx7ahcZYDJQ Ehz6UFZowQqth9k2DstNZBvySypAlkadadrXYv7iSJOEgo68DCqms2swTejTgUXK xey8J4kA1HR+5S+WobWWFbYsRGnpzhICDnAHuWW9qQ== -----END CERTIFICATE----- 2022-12-17T23:54:45Z DEBUG stderr= 2022-12-17T23:54:45Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:54:45Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:54:45Z DEBUG update_entry modlist [(2, 'userCertificate', [b'0\x82\x05[0\x82\x03\xc3\xa0\x03\x02\x01\x02\x02\x01\x080\r\x06\t*\x86H\x86\xf7\r\x01\x01\r\x05\x000:1\x180\x16\x06\x03U\x04\n\x0c\x0fREDACTED_DOMAIN.COM1\x1e0\x1c\x06\x03U\x04\x03\x0c\x15Certificate Authority0\x1e\x17\r221217235437Z\x17\r241217235437Z0=1\x180\x16\x06\x03U\x04\n\x0c\x0fREDACTED_DOMAIN.COM1!0\x1f\x06\x03U\x04\x03\x0c\x18master.redacted_domain.com0\x82\x01"0\r\x06\t*\x86H\x86\xf7\r\x01\x01\x01\x05\x00\x03\x82\x01\x0f\x000\x82\x01\n\x02\x82\x01\x01\x00\xc4}\xfd\x81\xd3\x1f\xf6\xbf\x06I!\x8e\x02r\xbeV\xd2\xa3\xd3\x97\x05\x8f\n2\x83\x8c\x7f\xc0I}j<\xf6\x8e\x0c.\xc6\xbf\xd2\xeb<\xcf5\xf9\xc2<\xdd\x1ak\x02[5\x10\xeb\x15(\x89\xa7(\xe9\x03\xc4\xfb\xb0\\\x04\xbd\x02\xaf\xa8Y\xda\xf6\x9c\xceR\x9c\xe6\xeb\xb6\xe3\x07\x85\xc9\xda\x17\xea\xfe\x17k\xd2\xae\xe6\xf3\x05\xe6\xea\xf3\x01\xe4\x84\x06\xa8\xf1\x9f\x94\x11A\xd2H#\xdaw\xaf\xaes&/p\xaaA\x9d\x96\xb9X\x87[\xd9SK\x8d|~\x9a\x9f\x9fW\xde\xa4\x1a\x81P\xc1&Ar\xf2\x84]\x8b\xbfo\x87\x02\x03\x01\x00\x01\xa3\x82\x01\xe70\x82\x01\xe30\x1f\x06\x03U\x1d#\x04\x180\x16\x80\x14\x9c!\xcc\xe9\xa7p\xafO\x06\xfd\x95\xfeX_~\xc1\xf6g\xa1\xc60A\x06\x08+\x06\x01\x05\x05\x07\x01\x01\x0450301\x06\x08+\x06\x01\x05\x05\x070\x01\x86%http://ipa-ca.redacted_domain.com/ca/ocsp0\x0e\x06\x03U\x1d\x0f\x01\x01\xff\x04\x04\x03\x02\x04\xf00\x1d\x06\x03U\x1d%\x04\x160\x14\x06\x08+\x06\x01\x05\x05\x07\x03\x01\x06\x08+\x06\x01\x05\x05\x07\x03\x020z\x06\x03U\x1d\x1f\x04s0q0o\xa07\xa05\x863http://ipa-ca.redacted_domain.com/ipa/crl/MasterCRL.bin\xa24\xa42001\x0e0\x0c\x06\x03U\x04\n\x0c\x05ipaca1\x1e0\x1c\x06\x03U\x04\x03\x0c\x15Certificate Authority0\x1d\x06\x03U\x1d\x0e\x04\x16\x04\x145\xe8P\xf1\x89\xb7\xf9\x91_\xd7[![\xc7\x14\xccY\x8f\xa0\x04\xde0\xaa\x9b.\x90\xd2^)\xba\xa8\xac\\\xe72fx\xfc\xe09\xc3H\xa5TZ\x19f:\xb2I\x1fXg\xbb\x08\xc7\xe9\x9bI\x07\x1b\xa05\x93\x03M\x8fl\x01\x19\r\xff5"\x04xp\xfe\x99\x16\x84\\\xb0\xcf\xa3\xa7~\xdc\xfdx\x00\xdc{j\x17\x19`2P\x12\x1c\xfaPVh\xc1\n\xad\x87\xd96\x0e\xcbMd\x1b\xf2K*@\x96F\x9di\xda\xd7b\xfe\xe2H\x93\x84\x82\x8e\xbc\x0c*\xa6\xb3k0M\xe8\xd3\x81E\xca\xc5\xec\xbc\'\x89\x00\xd4t~\xe5/\x96\xa1\xb5\x96\x15\xb6,Di\xe9\xce\x12\x02\x0ep\x07\xb9e\xbd\xa9'])] 2022-12-17T23:54:45Z DEBUG update_entry modlist [(2, 'nsSSLClientAuth', [b'allowed']), (2, 'nsSSL3Ciphers', [b'default']), (2, 'allowWeakCipher', [b'off'])] 2022-12-17T23:54:45Z DEBUG update_entry modlist [(2, 'nsslapd-security', [b'on'])] 2022-12-17T23:54:45Z DEBUG update_entry modlist [(2, 'nsSSLPersonalitySSL', [b'Server-Cert']), (2, 'nsSSLToken', [b'internal (software)']), (2, 'nsSSLActivation', [b'on']), (2, 'objectclass', [b'top', b'nsEncryptionModule']), (2, 'cn', [b'RSA'])] 2022-12-17T23:54:45Z DEBUG step duration: dirsrv __enable_ssl 11.22 sec 2022-12-17T23:54:45Z DEBUG [2/3]: adding CA certificate entry 2022-12-17T23:54:45Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:54:45Z DEBUG Starting external process 2022-12-17T23:54:45Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/', '-L', '-f', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/pwdfile.txt'] 2022-12-17T23:54:45Z DEBUG Process finished, return code=0 2022-12-17T23:54:45Z DEBUG stdout= Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI REDACTED_DOMAIN.COM IPA CA CT,C,C Server-Cert u,u,u 2022-12-17T23:54:45Z DEBUG stderr= 2022-12-17T23:54:45Z DEBUG Starting external process 2022-12-17T23:54:45Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/', '-O', '--simple-self-signed', '-n', 'REDACTED_DOMAIN.COM IPA CA', '-f', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/pwdfile.txt'] 2022-12-17T23:54:45Z DEBUG Process finished, return code=0 2022-12-17T23:54:45Z DEBUG stdout="REDACTED_DOMAIN.COM IPA CA" [CN=Certificate Authority,O=REDACTED_DOMAIN.COM] 2022-12-17T23:54:45Z DEBUG stderr= 2022-12-17T23:54:45Z DEBUG Starting external process 2022-12-17T23:54:45Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/', '-L', '-n', 'REDACTED_DOMAIN.COM IPA CA', '-a', '-f', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/pwdfile.txt'] 2022-12-17T23:54:45Z DEBUG Process finished, return code=0 2022-12-17T23:54:45Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIElzCCAv+gAwIBAgIBATANBgkqhkiG9w0BAQsFADA6MRgwFgYDVQQKDA9NT05J VkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0y MjEyMTcyMzUyMjdaFw00MjEyMTcyMzUyMjdaMDoxGDAWBgNVBAoMD01PTklWQUdS T1VQLkNPTTEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MIIBojANBgkq hkiG9w0BAQEFAAOCAY8AMIIBigKCAYEApvkK92tmgf6gzc7YvEOKeMIM2vA4ib/a ZYGjNA/rs6KKAKc9ZA3WWi/jmiskXCA6iidKX0EEBtlwYiC/mmRV5CG61/JG7s68 OK0SIxHQi0Li2yKrbeGjFlcveJuM0baTGS3bA995lbiqGNfKNl1LoLGTJs7QPA/N AhX6xqTD91W35ueYO8n5G2rAlgyQAGGvBntFeZeH6tA4DrZkHzBgSe/YZkllAN4h J0QOiBHvibSYjvvHE/XhILTZ5ZkPdxZQ8f9LwYH7v8mELmG2BjX9ipE3QgBuZ1F+ ntmHGyX68ReF2j8Mq98Ja1r88Uxg7Bely1GCFtN1883pwM8cYH786LeN5ELaR1UP zrHCqWJs5P1aGFcUtaVHhJV1TrA9ifXdj9LOyUVrBRzjjqysLYUB9O1f81qXGZwO F2My603PCN6wpQTxDULNjiSH7oDGTIZ30n5zf0X7WoBprvcTH3hP23CzJUuIKvgD tLyiwJIVBlbBeEUa/HtBm55HxmYDBGihAgMBAAGjgacwgaQwHwYDVR0jBBgwFoAU nCHM6adwr08G/ZX+WF9+wfZnocYwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8E BAMCAcYwHQYDVR0OBBYEFJwhzOmncK9PBv2V/lhffsH2Z6HGMEEGCCsGAQUFBwEB BDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL2lwYS1jYS5tb25pdmFncm91cC5jb20v Y2Evb2NzcDANBgkqhkiG9w0BAQsFAAOCAYEAmk/NzYQfLywaP+vwIQxW7csqgWym AanHwHEwQa4nGs3be80jYPyr9u8x2yStxX93o5U3IwHyzMprSN5VehUT4RuFwzMa AscI3cjTtn0IL0GTEjeTMtUYvhj6bNg58tS1RRYDqUcI4Ug5r/KjPxfcTVDh7/XS X1MDgWwbf092Sx7+3OnBwxvkgk4xYthwRVfsPOT4UG5Wiad2q149ZYDWhzf+Kwft 5hBoY1ZSvxoNzXjXP5ch25ObVpmw03OYFLWtMDfcsKJim+VvS0EN9TvYPqcLYzkf EfPn4kGwg/1+oz6zT6ODkfAdePqF3FqVD93ZqlX6o6R0jILJ+lLVDhKD9hZ/tJE/ 1JnBjdIuXzGQgzCayXCpSIkoDYVDtxFHp5p0s5Xm3kcci9bmB9P8XtlVQ25ha2fM l4/cWzI5U9kn7NSrksxBqlwLYf3ffCZ6bkBwBzto6xst4grBqvDy1xusxEafx6+V ZAxH5ep/2YvBzDDclc5WvZ447jL6iPS+P9lT -----END CERTIFICATE----- 2022-12-17T23:54:45Z DEBUG stderr= 2022-12-17T23:54:45Z DEBUG step duration: dirsrv __upload_ca_cert 0.15 sec 2022-12-17T23:54:45Z DEBUG [3/3]: restarting directory server 2022-12-17T23:54:45Z DEBUG Destroyed connection context.ldap2_140111978781200 2022-12-17T23:54:45Z DEBUG Starting external process 2022-12-17T23:54:45Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2022-12-17T23:54:45Z DEBUG Process finished, return code=0 2022-12-17T23:54:45Z DEBUG stdout= 2022-12-17T23:54:45Z DEBUG stderr= 2022-12-17T23:54:45Z DEBUG Starting external process 2022-12-17T23:54:45Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:54:49Z DEBUG Process finished, return code=0 2022-12-17T23:54:49Z DEBUG stdout= 2022-12-17T23:54:49Z DEBUG stderr= 2022-12-17T23:54:49Z DEBUG Starting external process 2022-12-17T23:54:49Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:54:49Z DEBUG Process finished, return code=0 2022-12-17T23:54:49Z DEBUG stdout=active 2022-12-17T23:54:49Z DEBUG stderr= 2022-12-17T23:54:49Z DEBUG wait_for_open_ports: localhost [389] timeout 120 2022-12-17T23:54:49Z DEBUG waiting for port: 389 2022-12-17T23:54:49Z DEBUG SUCCESS: port: 389 2022-12-17T23:54:49Z DEBUG Restart of dirsrv@REDACTED_DOMAIN-COM.service complete 2022-12-17T23:54:49Z DEBUG Starting external process 2022-12-17T23:54:49Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:54:49Z DEBUG Process finished, return code=0 2022-12-17T23:54:49Z DEBUG stdout=active 2022-12-17T23:54:49Z DEBUG stderr= 2022-12-17T23:54:50Z DEBUG Created connection context.ldap2_140111978781200 2022-12-17T23:54:50Z DEBUG step duration: dirsrv __restart_instance 4.70 sec 2022-12-17T23:54:50Z DEBUG Done configuring directory server (dirsrv). 2022-12-17T23:54:50Z DEBUG service duration: dirsrv 16.06 sec 2022-12-17T23:54:50Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:54:50Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:54:50Z DEBUG Starting external process 2022-12-17T23:54:50Z DEBUG args=['/bin/systemctl', 'stop', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:54:51Z DEBUG Process finished, return code=0 2022-12-17T23:54:51Z DEBUG stdout= 2022-12-17T23:54:51Z DEBUG stderr= 2022-12-17T23:54:51Z DEBUG Stop of pki-tomcatd@pki-tomcat.service complete 2022-12-17T23:54:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:54:51Z DEBUG Ensuring that service pki-tomcatd@pki-tomcat is not running while the next set of commands is being executed. 2022-12-17T23:54:51Z DEBUG Starting external process 2022-12-17T23:54:51Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:54:51Z DEBUG Process finished, return code=3 2022-12-17T23:54:51Z DEBUG stdout=inactive 2022-12-17T23:54:51Z DEBUG stderr= 2022-12-17T23:54:51Z DEBUG Service pki-tomcatd@pki-tomcat is not running, continue. 2022-12-17T23:54:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:54:51Z DEBUG Set up lightweight CA key retrieval 2022-12-17T23:54:51Z DEBUG Creating principal 2022-12-17T23:54:51Z DEBUG Starting external process 2022-12-17T23:54:51Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey dogtag/master.redacted_domain.com@REDACTED_DOMAIN.COM', '-x', 'ipa-setup-override-restrictions'] 2022-12-17T23:54:51Z DEBUG Process finished, return code=0 2022-12-17T23:54:51Z DEBUG stdout=Authenticating as principal root/admin@REDACTED_DOMAIN.COM with password. Principal "dogtag/master.redacted_domain.com@REDACTED_DOMAIN.COM" created. 2022-12-17T23:54:51Z DEBUG stderr=No policy specified for dogtag/master.redacted_domain.com@REDACTED_DOMAIN.COM; defaulting to no policy 2022-12-17T23:54:51Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:54:51Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:54:51Z DEBUG Retrieving keytab 2022-12-17T23:54:51Z DEBUG Starting external process 2022-12-17T23:54:51Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/pki/pki-tomcat/dogtag.keytab dogtag/master.redacted_domain.com@REDACTED_DOMAIN.COM', '-x', 'ipa-setup-override-restrictions'] 2022-12-17T23:54:51Z DEBUG Process finished, return code=0 2022-12-17T23:54:51Z DEBUG stdout=Authenticating as principal root/admin@REDACTED_DOMAIN.COM with password. Entry for principal dogtag/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. 2022-12-17T23:54:51Z DEBUG stderr= 2022-12-17T23:54:51Z DEBUG Creating Custodia keys 2022-12-17T23:54:52Z DEBUG Configuring key retriever 2022-12-17T23:54:52Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:54:52Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:54:52Z DEBUG Destroyed connection context.ldap2_140111978781200 2022-12-17T23:54:52Z DEBUG Starting external process 2022-12-17T23:54:52Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:54:58Z DEBUG Process finished, return code=0 2022-12-17T23:54:58Z DEBUG stdout= 2022-12-17T23:54:58Z DEBUG stderr= 2022-12-17T23:54:58Z DEBUG Restart of dirsrv@REDACTED_DOMAIN-COM.service complete 2022-12-17T23:54:58Z DEBUG Created connection context.ldap2_140111978781200 2022-12-17T23:54:58Z DEBUG Starting external process 2022-12-17T23:54:58Z DEBUG args=['/bin/systemctl', 'start', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:55:16Z DEBUG Process finished, return code=0 2022-12-17T23:55:16Z DEBUG stdout= 2022-12-17T23:55:16Z DEBUG stderr= 2022-12-17T23:55:16Z DEBUG Starting external process 2022-12-17T23:55:16Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:55:16Z DEBUG Process finished, return code=0 2022-12-17T23:55:16Z DEBUG stdout=active 2022-12-17T23:55:16Z DEBUG stderr= 2022-12-17T23:55:16Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 120 2022-12-17T23:55:16Z DEBUG waiting for port: 8080 2022-12-17T23:55:16Z DEBUG SUCCESS: port: 8080 2022-12-17T23:55:16Z DEBUG waiting for port: 8443 2022-12-17T23:55:16Z DEBUG SUCCESS: port: 8443 2022-12-17T23:55:16Z DEBUG Start of pki-tomcatd@pki-tomcat.service complete 2022-12-17T23:55:18Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:55:18Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:55:18Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:55:18Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:55:18Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:55:18Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:55:18Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:55:18Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:55:18Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:55:19Z DEBUG Created connection context.ldap2_140053013141904 2022-12-17T23:55:19Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:19Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:55:19Z DEBUG Configuring ipa-otpd 2022-12-17T23:55:19Z DEBUG [1/2]: starting ipa-otpd 2022-12-17T23:55:19Z DEBUG Starting external process 2022-12-17T23:55:19Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-otpd.socket'] 2022-12-17T23:55:19Z DEBUG Process finished, return code=3 2022-12-17T23:55:19Z DEBUG stdout=inactive 2022-12-17T23:55:19Z DEBUG stderr= 2022-12-17T23:55:19Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:19Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:19Z DEBUG Starting external process 2022-12-17T23:55:19Z DEBUG args=['/bin/systemctl', 'restart', 'ipa-otpd.socket'] 2022-12-17T23:55:19Z DEBUG Process finished, return code=0 2022-12-17T23:55:19Z DEBUG stdout= 2022-12-17T23:55:19Z DEBUG stderr= 2022-12-17T23:55:19Z DEBUG Starting external process 2022-12-17T23:55:19Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-otpd.socket'] 2022-12-17T23:55:19Z DEBUG Process finished, return code=0 2022-12-17T23:55:19Z DEBUG stdout=active 2022-12-17T23:55:19Z DEBUG stderr= 2022-12-17T23:55:19Z DEBUG Restart of ipa-otpd.socket complete 2022-12-17T23:55:19Z DEBUG step duration: ipa-otpd __start 0.04 sec 2022-12-17T23:55:19Z DEBUG [2/2]: configuring ipa-otpd to start on boot 2022-12-17T23:55:19Z DEBUG Starting external process 2022-12-17T23:55:19Z DEBUG args=['/bin/systemctl', 'is-enabled', 'ipa-otpd.socket'] 2022-12-17T23:55:19Z DEBUG Process finished, return code=1 2022-12-17T23:55:19Z DEBUG stdout=disabled 2022-12-17T23:55:19Z DEBUG stderr= 2022-12-17T23:55:19Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:19Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:19Z DEBUG Starting external process 2022-12-17T23:55:19Z DEBUG args=['/bin/systemctl', 'unmask', 'ipa-otpd.socket'] 2022-12-17T23:55:20Z DEBUG Process finished, return code=0 2022-12-17T23:55:20Z DEBUG stdout= 2022-12-17T23:55:20Z DEBUG stderr= 2022-12-17T23:55:20Z DEBUG Starting external process 2022-12-17T23:55:20Z DEBUG args=['/bin/systemctl', 'disable', 'ipa-otpd.socket'] 2022-12-17T23:55:20Z DEBUG Process finished, return code=0 2022-12-17T23:55:20Z DEBUG stdout= 2022-12-17T23:55:20Z DEBUG stderr= 2022-12-17T23:55:20Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:55:20Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:55:20Z DEBUG step duration: ipa-otpd __enable 0.93 sec 2022-12-17T23:55:20Z DEBUG Done configuring ipa-otpd. 2022-12-17T23:55:20Z DEBUG service duration: ipa-otpd 0.97 sec 2022-12-17T23:55:22Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:55:22Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:55:22Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:55:22Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:55:22Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:55:22Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:55:22Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:55:22Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:55:22Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:55:22Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:55:23Z DEBUG Created connection context.ldap2_140472260056272 2022-12-17T23:55:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:23Z DEBUG Configuring the web interface (httpd) 2022-12-17T23:55:23Z DEBUG [1/22]: stopping httpd 2022-12-17T23:55:23Z DEBUG Starting external process 2022-12-17T23:55:23Z DEBUG args=['/bin/systemctl', 'is-active', 'httpd.service'] 2022-12-17T23:55:23Z DEBUG Process finished, return code=3 2022-12-17T23:55:23Z DEBUG stdout=inactive 2022-12-17T23:55:23Z DEBUG stderr= 2022-12-17T23:55:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:23Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:23Z DEBUG Starting external process 2022-12-17T23:55:23Z DEBUG args=['/bin/systemctl', 'stop', 'httpd.service'] 2022-12-17T23:55:23Z DEBUG Process finished, return code=0 2022-12-17T23:55:23Z DEBUG stdout= 2022-12-17T23:55:23Z DEBUG stderr= 2022-12-17T23:55:23Z DEBUG Stop of httpd.service complete 2022-12-17T23:55:23Z DEBUG step duration: httpd __stop 0.02 sec 2022-12-17T23:55:23Z DEBUG [2/22]: backing up ssl.conf 2022-12-17T23:55:23Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/ssl.conf' 2022-12-17T23:55:23Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:55:23Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/ssl.conf' 2022-12-17T23:55:23Z DEBUG -> Not backing up - already have a copy of '/etc/httpd/conf.d/ssl.conf' 2022-12-17T23:55:23Z DEBUG step duration: httpd backup_ssl_conf 0.00 sec 2022-12-17T23:55:23Z DEBUG [3/22]: disabling nss.conf 2022-12-17T23:55:23Z DEBUG step duration: httpd disable_nss_conf 0.00 sec 2022-12-17T23:55:23Z DEBUG [4/22]: configuring mod_ssl certificate paths 2022-12-17T23:55:23Z DEBUG step duration: httpd configure_mod_ssl_certs 0.00 sec 2022-12-17T23:55:23Z DEBUG [5/22]: setting mod_ssl protocol list 2022-12-17T23:55:23Z DEBUG step duration: httpd set_mod_ssl_protocol 0.00 sec 2022-12-17T23:55:23Z DEBUG [6/22]: configuring mod_ssl log directory 2022-12-17T23:55:23Z DEBUG step duration: httpd set_mod_ssl_logdir 0.00 sec 2022-12-17T23:55:23Z DEBUG [7/22]: disabling mod_ssl OCSP 2022-12-17T23:55:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:23Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:23Z DEBUG step duration: httpd disable_mod_ssl_ocsp 0.02 sec 2022-12-17T23:55:23Z DEBUG [8/22]: adding URL rewriting rules 2022-12-17T23:55:23Z DEBUG step duration: httpd __add_include 0.00 sec 2022-12-17T23:55:23Z DEBUG [9/22]: configuring httpd 2022-12-17T23:55:23Z DEBUG Starting external process 2022-12-17T23:55:23Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:55:23Z DEBUG Process finished, return code=0 2022-12-17T23:55:23Z DEBUG stdout= 2022-12-17T23:55:23Z DEBUG stderr= 2022-12-17T23:55:23Z DEBUG Starting external process 2022-12-17T23:55:23Z DEBUG args=['/sbin/restorecon', '/etc/systemd/system/httpd.service.d/ipa.conf'] 2022-12-17T23:55:23Z DEBUG Process finished, return code=0 2022-12-17T23:55:23Z DEBUG stdout= 2022-12-17T23:55:23Z DEBUG stderr= 2022-12-17T23:55:23Z DEBUG Starting external process 2022-12-17T23:55:23Z DEBUG args=['/bin/systemctl', '--system', 'daemon-reload'] 2022-12-17T23:55:24Z DEBUG Process finished, return code=0 2022-12-17T23:55:24Z DEBUG stdout= 2022-12-17T23:55:24Z DEBUG stderr= 2022-12-17T23:55:24Z DEBUG Starting external process 2022-12-17T23:55:24Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:55:24Z DEBUG Process finished, return code=0 2022-12-17T23:55:24Z DEBUG stdout= 2022-12-17T23:55:24Z DEBUG stderr= 2022-12-17T23:55:24Z DEBUG Starting external process 2022-12-17T23:55:24Z DEBUG args=['/sbin/restorecon', '/etc/httpd/conf.modules.d/02-ipa-wsgi.conf'] 2022-12-17T23:55:24Z DEBUG Process finished, return code=0 2022-12-17T23:55:24Z DEBUG stdout= 2022-12-17T23:55:24Z DEBUG stderr= 2022-12-17T23:55:24Z DEBUG Starting external process 2022-12-17T23:55:24Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:55:24Z DEBUG Process finished, return code=0 2022-12-17T23:55:24Z DEBUG stdout= 2022-12-17T23:55:24Z DEBUG stderr= 2022-12-17T23:55:24Z DEBUG Starting external process 2022-12-17T23:55:24Z DEBUG args=['/sbin/restorecon', '/etc/httpd/alias'] 2022-12-17T23:55:24Z DEBUG Process finished, return code=0 2022-12-17T23:55:24Z DEBUG stdout= 2022-12-17T23:55:24Z DEBUG stderr= 2022-12-17T23:55:24Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/ipa.conf' 2022-12-17T23:55:24Z DEBUG -> Not backing up - '/etc/httpd/conf.d/ipa.conf' doesn't exist 2022-12-17T23:55:24Z DEBUG Backing up system configuration file '/etc/httpd/conf.d/ipa-rewrite.conf' 2022-12-17T23:55:24Z DEBUG -> Not backing up - '/etc/httpd/conf.d/ipa-rewrite.conf' doesn't exist 2022-12-17T23:55:24Z DEBUG step duration: httpd __configure_http 0.40 sec 2022-12-17T23:55:24Z DEBUG [10/22]: setting up httpd keytab 2022-12-17T23:55:24Z DEBUG raw: service_add('HTTP/master.redacted_domain.com@REDACTED_DOMAIN.COM', force=True, version='2.251') 2022-12-17T23:55:24Z DEBUG service_add(ipapython.kerberos.Principal('HTTP/master.redacted_domain.com@REDACTED_DOMAIN.COM'), force=True, skip_host_check=False, all=False, raw=False, version='2.251', no_members=False) 2022-12-17T23:55:24Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:55:24Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:55:24Z DEBUG raw: host_show('master.redacted_domain.com', version='2.251') 2022-12-17T23:55:24Z DEBUG host_show('master.redacted_domain.com', rights=False, all=False, raw=False, version='2.251', no_members=False) 2022-12-17T23:55:24Z DEBUG Backing up system configuration file '/var/lib/ipa/gssproxy/http.keytab' 2022-12-17T23:55:24Z DEBUG -> Not backing up - '/var/lib/ipa/gssproxy/http.keytab' doesn't exist 2022-12-17T23:55:24Z DEBUG Starting external process 2022-12-17T23:55:24Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/var/lib/ipa/gssproxy/http.keytab', '-p', 'HTTP/master.redacted_domain.com@REDACTED_DOMAIN.COM', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:55:24Z DEBUG Process finished, return code=0 2022-12-17T23:55:24Z DEBUG stdout= 2022-12-17T23:55:24Z DEBUG stderr=Keytab successfully retrieved and stored in: /var/lib/ipa/gssproxy/http.keytab 2022-12-17T23:55:24Z DEBUG step duration: httpd request_service_keytab 0.29 sec 2022-12-17T23:55:24Z DEBUG [11/22]: configuring Gssproxy 2022-12-17T23:55:24Z DEBUG Starting external process 2022-12-17T23:55:24Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:55:24Z DEBUG Process finished, return code=0 2022-12-17T23:55:24Z DEBUG stdout= 2022-12-17T23:55:24Z DEBUG stderr= 2022-12-17T23:55:24Z DEBUG Starting external process 2022-12-17T23:55:24Z DEBUG args=['/sbin/restorecon', '/etc/gssproxy/10-ipa.conf'] 2022-12-17T23:55:24Z DEBUG Process finished, return code=0 2022-12-17T23:55:24Z DEBUG stdout= 2022-12-17T23:55:24Z DEBUG stderr= 2022-12-17T23:55:24Z DEBUG Starting external process 2022-12-17T23:55:24Z DEBUG args=['/bin/systemctl', 'restart', 'gssproxy.service'] 2022-12-17T23:55:24Z DEBUG Process finished, return code=0 2022-12-17T23:55:24Z DEBUG stdout= 2022-12-17T23:55:24Z DEBUG stderr= 2022-12-17T23:55:24Z DEBUG Starting external process 2022-12-17T23:55:24Z DEBUG args=['/bin/systemctl', 'is-active', 'gssproxy.service'] 2022-12-17T23:55:24Z DEBUG Process finished, return code=0 2022-12-17T23:55:24Z DEBUG stdout=active 2022-12-17T23:55:24Z DEBUG stderr= 2022-12-17T23:55:24Z DEBUG Restart of gssproxy.service complete 2022-12-17T23:55:24Z DEBUG step duration: httpd configure_gssproxy 0.07 sec 2022-12-17T23:55:24Z DEBUG [12/22]: setting up ssl 2022-12-17T23:55:24Z DEBUG certmonger request is in state 'GENERATING_KEY_PAIR' 2022-12-17T23:55:25Z DEBUG certmonger request is in state 'SUBMITTING' 2022-12-17T23:55:26Z DEBUG certmonger request is in state 'POST_SAVED_CERT' 2022-12-17T23:55:26Z DEBUG certmonger request is in state 'MONITORING' 2022-12-17T23:55:26Z DEBUG Cert request 20221217235524 was successful 2022-12-17T23:55:26Z DEBUG update_entry modlist [(2, 'userCertificate', [b'0\x82\x05s0\x82\x03\xdb\xa0\x03\x02\x01\x02\x02\x01\t0\r\x06\t*\x86H\x86\xf7\r\x01\x01\r\x05\x000:1\x180\x16\x06\x03U\x04\n\x0c\x0fREDACTED_DOMAIN.COM1\x1e0\x1c\x06\x03U\x04\x03\x0c\x15Certificate Authority0\x1e\x17\r221217235525Z\x17\r241217235525Z0=1\x180\x16\x06\x03U\x04\n\x0c\x0fREDACTED_DOMAIN.COM1!0\x1f\x06\x03U\x04\x03\x0c\x18master.redacted_domain.com0\x82\x01"0\r\x06\t*\x86H\x86\xf7\r\x01\x01\x01\x05\x00\x03\x82\x01\x0f\x000\x82\x01\n\x02\x82\x01\x01\x00\xdf^\xc7H\xb9\xec\x07\x8dU\xdb\xc7s\xa8\x94\xdf\xdek\xf5G\xd3Y\x04\x0b\xcf\x83\xa5Y\x8f/U\xf5\xb2g\xbaq\xee20m\xd0\xcc\xdd\xa8\xa7\x94\x8b=\xb9\x90\xfd\x93\xb5\xcc\xb5e(\xda\x1ex\xb4\xbc\x89\x9d\x0e\xbb\xf7\x03\xc9H\xb7,\x9cuG\x83\x85\xe84\xce\xa6Y\xd7pRu\x08\xca\\}\x0e\x0f\x9ck\xed\xf4\x1e0\xad\');\x8d~\x02\x18n\x91Y\xf2(\x98\x10\xc8\x9c\x8bI\'\x9d\xa5+\xc5\x92\xc6;\x1d8\xd0\xc3aM\x06\x94\xf8J\x002*\xe7\x00\xb0G\xb6\xc1\xc1\xe4\x04\x8a\xda\xbb\xf6\xc7\xfb\xac\xcb\xdb\xa2\xa5\x14\x1e=\x90N\x8aVM\x1e\xa2\x92\xef\x9b\xf8\x0c\xe41\xfbc\x14\x81\xa1\'I\xad\x96\xfa\x17`T`\xc6\x96\x0e\x8c\xd4\xae`[g\xd0\x98`VT\xf8\xee\xc8\xa8\xa5q\xe7v\x8c\xdc\xf9\xa9*\xc7}\x99\x0c\x0f\xbe[\xb0G\xd4\xb8\\\xc3Z3T\x95\x07\x07\x1b\xce\xd4\xf2\x1c\x80\xbe\x8d\xb1\xe9\x1c}\xa9;\xd7\x91F\x15\x1a\x88%o\x02\x03\x01\x00\x01\xa3\x82\x01\xff0\x82\x01\xfb0\x1f\x06\x03U\x1d#\x04\x180\x16\x80\x14\x9c!\xcc\xe9\xa7p\xafO\x06\xfd\x95\xfeX_~\xc1\xf6g\xa1\xc60A\x06\x08+\x06\x01\x05\x05\x07\x01\x01\x0450301\x06\x08+\x06\x01\x05\x05\x070\x01\x86%http://ipa-ca.redacted_domain.com/ca/ocsp0\x0e\x06\x03U\x1d\x0f\x01\x01\xff\x04\x04\x03\x02\x04\xf00\x1d\x06\x03U\x1d%\x04\x160\x14\x06\x08+\x06\x01\x05\x05\x07\x03\x01\x06\x08+\x06\x01\x05\x05\x07\x03\x020z\x06\x03U\x1d\x1f\x04s0q0o\xa07\xa05\x863http://ipa-ca.redacted_domain.com/ipa/crl/MasterCRL.bin\xa24\xa42001\x0e0\x0c\x06\x03U\x04\n\x0c\x05ipaca1\x1e0\x1c\x06\x03U\x04\x03\x0c\x15Certificate Authority0\x1d\x06\x03U\x1d\x0e\x04\x16\x04\x14\xf7\x11\x1e8\x11c\xcd\xede\xfcP\xd07\x9e\xbe\xb4\x02\xbf\x88\x050\x81\xca\x06\x03U\x1d\x11\x04\x81\xc20\x81\xbf\x82\x18master.redacted_domain.com\x82\x16ipa-ca.redacted_domain.com\xa0=\x06\n+\x06\x01\x04\x01\x827\x14\x02\x03\xa0/\x0c-HTTP/master.redacted_domain.com@REDACTED_DOMAIN.COM\xa0L\x06\x06+\x06\x01\x05\x02\x02\xa0B0@\xa0\x11\x1b\x0fREDACTED_DOMAIN.COM\xa1+0)\xa0\x03\x02\x01\x01\xa1"0 \x1b\x04HTTP\x1b\x18master.redacted_domain.com0\r\x06\t*\x86H\x86\xf7\r\x01\x01\r\x05\x00\x03\x82\x01\x81\x00\x1e\xf4\x8a\x87q\x83:\xaa<\x16\xfb\xb4\xbe\x07\x8d\xed\xc5\xd6\xc2\xec\x14\x8f\xe3M}J"\xb0\xcf\xb8\x03`T\xaa\\\xb8\xd8\xfe\x1av\x96J\xaa\xa4\xaf\x9b:+\r^/\x87h\x07Bt\x90I\xffD/\x9eY\x17\xac\xdd\\i\x9d\x90#\xa2b\x98\xaa/)\xc7\xd2\xbe\x8b\xa5R\x12\xb7\x84\xb9t\xb7\x9c\x84\x07-\x06\xd9\xfd\x8b\xeaV\xae\x89\x07@&\x94\x96\x97z\x12\xa7j\x9e\x1b\xae\x88F\xcd\xd3\x85\x93v\x970p\x05\x8eT\n\x9e\x12\xbb\xbf\xe0+\x81\xa5\x8cr\x19\xa7\xce>\x814\xd1\xaaF`\xc0\x897\x9am3\xa4\x14\xe4|\x1a\xda\xc9ny\x1c\xe7\xb7\xecbd\t\x01\xdb\xbb\x0b=\x93\xf5\xd8\xc7\xa6\xe9\xde\x95<\xd9\x95.YI\xe3\xf25\x15\x8b\xa4\x8a/}(=\xbb\xe7\xcc\x96w\xd1\xdd\xe5\x16\xea\t\x97\x94\xb9\xd1k\xfb\xb5\xf2\xc5\xf7\x1f\x151\xe7\xe2\x1d\tIX\x1a}\xcf\xaf\x00\'\x83\x13t\x15\xa5^\xbd\xdf\xfb\x0b,\\\xef\xf7R\xf9\xc3\x96\x10\x0fVf,D\xae\x16\xa2-,\xf9\xb7O\xaay\xb1o\x17!\xc5\x02\xa7'])] 2022-12-17T23:55:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:26Z DEBUG step duration: httpd __setup_ssl 2.51 sec 2022-12-17T23:55:26Z DEBUG [13/22]: configure certmonger for renewals 2022-12-17T23:55:26Z DEBUG Starting external process 2022-12-17T23:55:26Z DEBUG args=['/bin/systemctl', 'is-active', 'certmonger.service'] 2022-12-17T23:55:27Z DEBUG Process finished, return code=0 2022-12-17T23:55:27Z DEBUG stdout=active 2022-12-17T23:55:27Z DEBUG stderr= 2022-12-17T23:55:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:27Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:27Z DEBUG step duration: httpd configure_certmonger_renewal_guard 0.32 sec 2022-12-17T23:55:27Z DEBUG [14/22]: publish CA cert 2022-12-17T23:55:27Z DEBUG step duration: httpd __publish_ca_cert 0.01 sec 2022-12-17T23:55:27Z DEBUG [15/22]: clean up any existing httpd ccaches 2022-12-17T23:55:27Z DEBUG Starting external process 2022-12-17T23:55:27Z DEBUG args=['/bin/systemd-tmpfiles', '--create', '--prefix', '/run/ipa/ccaches'] 2022-12-17T23:55:27Z DEBUG Process finished, return code=0 2022-12-17T23:55:27Z DEBUG stdout= 2022-12-17T23:55:27Z DEBUG stderr= 2022-12-17T23:55:27Z DEBUG step duration: httpd remove_httpd_ccaches 0.02 sec 2022-12-17T23:55:27Z DEBUG [16/22]: enable ccache sweep 2022-12-17T23:55:27Z DEBUG Starting external process 2022-12-17T23:55:27Z DEBUG args=['/bin/systemctl', 'enable', 'ipa-ccache-sweep.timer'] 2022-12-17T23:55:27Z DEBUG Process finished, return code=0 2022-12-17T23:55:27Z DEBUG stdout= 2022-12-17T23:55:27Z DEBUG stderr=Created symlink /etc/systemd/system/timers.target.wants/ipa-ccache-sweep.timer → /usr/lib/systemd/system/ipa-ccache-sweep.timer. 2022-12-17T23:55:27Z DEBUG step duration: httpd enable_ccache_sweep 0.43 sec 2022-12-17T23:55:27Z DEBUG [17/22]: configuring SELinux for httpd 2022-12-17T23:55:27Z DEBUG Starting external process 2022-12-17T23:55:27Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-17T23:55:27Z DEBUG Process finished, return code=0 2022-12-17T23:55:27Z DEBUG stdout= 2022-12-17T23:55:27Z DEBUG stderr= 2022-12-17T23:55:27Z DEBUG Starting external process 2022-12-17T23:55:27Z DEBUG args=['/usr/sbin/getsebool', 'httpd_can_network_connect'] 2022-12-17T23:55:27Z DEBUG Process finished, return code=0 2022-12-17T23:55:27Z DEBUG stdout=httpd_can_network_connect --> off 2022-12-17T23:55:27Z DEBUG stderr= 2022-12-17T23:55:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:27Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:27Z DEBUG Starting external process 2022-12-17T23:55:27Z DEBUG args=['/usr/sbin/getsebool', 'httpd_manage_ipa'] 2022-12-17T23:55:27Z DEBUG Process finished, return code=0 2022-12-17T23:55:27Z DEBUG stdout=httpd_manage_ipa --> off 2022-12-17T23:55:27Z DEBUG stderr= 2022-12-17T23:55:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:27Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:27Z DEBUG Starting external process 2022-12-17T23:55:27Z DEBUG args=['/usr/sbin/getsebool', 'httpd_run_ipa'] 2022-12-17T23:55:27Z DEBUG Process finished, return code=0 2022-12-17T23:55:27Z DEBUG stdout=httpd_run_ipa --> off 2022-12-17T23:55:27Z DEBUG stderr= 2022-12-17T23:55:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:27Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:27Z DEBUG Starting external process 2022-12-17T23:55:27Z DEBUG args=['/usr/sbin/getsebool', 'httpd_dbus_sssd'] 2022-12-17T23:55:27Z DEBUG Process finished, return code=0 2022-12-17T23:55:27Z DEBUG stdout=httpd_dbus_sssd --> off 2022-12-17T23:55:27Z DEBUG stderr= 2022-12-17T23:55:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:27Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:27Z DEBUG Starting external process 2022-12-17T23:55:27Z DEBUG args=['/usr/sbin/setsebool', '-P', 'httpd_can_network_connect=on', 'httpd_manage_ipa=on', 'httpd_run_ipa=on', 'httpd_dbus_sssd=on'] 2022-12-17T23:55:28Z DEBUG Process finished, return code=0 2022-12-17T23:55:28Z DEBUG stdout= 2022-12-17T23:55:28Z DEBUG stderr= 2022-12-17T23:55:28Z DEBUG step duration: httpd configure_selinux_for_httpd 1.13 sec 2022-12-17T23:55:28Z DEBUG [18/22]: create KDC proxy config 2022-12-17T23:55:28Z DEBUG Backing up system configuration file '/etc/ipa/kdcproxy/ipa-kdc-proxy.conf' 2022-12-17T23:55:28Z DEBUG -> Not backing up - '/etc/ipa/kdcproxy/ipa-kdc-proxy.conf' doesn't exist 2022-12-17T23:55:28Z DEBUG step duration: httpd create_kdcproxy_conf 0.00 sec 2022-12-17T23:55:28Z DEBUG [19/22]: enable KDC proxy 2022-12-17T23:55:28Z DEBUG update_entry modlist [(0, 'ipaconfigstring', [b'kdcProxyEnabled'])] 2022-12-17T23:55:28Z DEBUG service KDC has all config values set 2022-12-17T23:55:28Z DEBUG step duration: httpd enable_kdcproxy 0.01 sec 2022-12-17T23:55:28Z DEBUG [20/22]: starting httpd 2022-12-17T23:55:28Z DEBUG Starting external process 2022-12-17T23:55:28Z DEBUG args=['/bin/systemctl', 'start', 'httpd.service'] 2022-12-17T23:55:29Z DEBUG Process finished, return code=0 2022-12-17T23:55:29Z DEBUG stdout= 2022-12-17T23:55:29Z DEBUG stderr= 2022-12-17T23:55:29Z DEBUG Starting external process 2022-12-17T23:55:29Z DEBUG args=['/bin/systemctl', 'is-active', 'httpd.service'] 2022-12-17T23:55:29Z DEBUG Process finished, return code=0 2022-12-17T23:55:29Z DEBUG stdout=active 2022-12-17T23:55:29Z DEBUG stderr= 2022-12-17T23:55:29Z DEBUG Start of httpd.service complete 2022-12-17T23:55:29Z DEBUG step duration: httpd start 1.01 sec 2022-12-17T23:55:29Z DEBUG [21/22]: configuring httpd to start on boot 2022-12-17T23:55:29Z DEBUG Starting external process 2022-12-17T23:55:29Z DEBUG args=['/bin/systemctl', 'is-enabled', 'httpd.service'] 2022-12-17T23:55:29Z DEBUG Process finished, return code=1 2022-12-17T23:55:29Z DEBUG stdout=disabled 2022-12-17T23:55:29Z DEBUG stderr= 2022-12-17T23:55:29Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:29Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:29Z DEBUG Starting external process 2022-12-17T23:55:29Z DEBUG args=['/bin/systemctl', 'unmask', 'httpd.service'] 2022-12-17T23:55:30Z DEBUG Process finished, return code=0 2022-12-17T23:55:30Z DEBUG stdout= 2022-12-17T23:55:30Z DEBUG stderr= 2022-12-17T23:55:30Z DEBUG Starting external process 2022-12-17T23:55:30Z DEBUG args=['/bin/systemctl', 'disable', 'httpd.service'] 2022-12-17T23:55:30Z DEBUG Process finished, return code=0 2022-12-17T23:55:30Z DEBUG stdout= 2022-12-17T23:55:30Z DEBUG stderr= 2022-12-17T23:55:30Z DEBUG step duration: httpd __enable 0.93 sec 2022-12-17T23:55:30Z DEBUG [22/22]: enabling oddjobd 2022-12-17T23:55:30Z DEBUG Starting external process 2022-12-17T23:55:30Z DEBUG args=['/bin/systemctl', 'is-active', 'oddjobd.service'] 2022-12-17T23:55:30Z DEBUG Process finished, return code=3 2022-12-17T23:55:30Z DEBUG stdout=inactive 2022-12-17T23:55:30Z DEBUG stderr= 2022-12-17T23:55:30Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:30Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:30Z DEBUG Starting external process 2022-12-17T23:55:30Z DEBUG args=['/bin/systemctl', 'is-enabled', 'oddjobd.service'] 2022-12-17T23:55:30Z DEBUG Process finished, return code=1 2022-12-17T23:55:30Z DEBUG stdout=disabled 2022-12-17T23:55:30Z DEBUG stderr= 2022-12-17T23:55:30Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:30Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:30Z DEBUG Starting external process 2022-12-17T23:55:30Z DEBUG args=['/bin/systemctl', 'enable', 'oddjobd.service'] 2022-12-17T23:55:31Z DEBUG Process finished, return code=0 2022-12-17T23:55:31Z DEBUG stdout= 2022-12-17T23:55:31Z DEBUG stderr=Created symlink /etc/systemd/system/multi-user.target.wants/oddjobd.service → /usr/lib/systemd/system/oddjobd.service. 2022-12-17T23:55:31Z DEBUG Starting external process 2022-12-17T23:55:31Z DEBUG args=['/bin/systemctl', 'start', 'oddjobd.service'] 2022-12-17T23:55:31Z DEBUG Process finished, return code=0 2022-12-17T23:55:31Z DEBUG stdout= 2022-12-17T23:55:31Z DEBUG stderr= 2022-12-17T23:55:31Z DEBUG Starting external process 2022-12-17T23:55:31Z DEBUG args=['/bin/systemctl', 'is-active', 'oddjobd.service'] 2022-12-17T23:55:31Z DEBUG Process finished, return code=0 2022-12-17T23:55:31Z DEBUG stdout=active 2022-12-17T23:55:31Z DEBUG stderr= 2022-12-17T23:55:31Z DEBUG Start of oddjobd.service complete 2022-12-17T23:55:31Z DEBUG step duration: httpd enable_and_start_oddjobd 0.53 sec 2022-12-17T23:55:31Z DEBUG Done configuring the web interface (httpd). 2022-12-17T23:55:31Z DEBUG service duration: httpd 7.71 sec 2022-12-17T23:55:31Z DEBUG Configuring Kerberos KDC (krb5kdc) 2022-12-17T23:55:31Z DEBUG [1/1]: installing X509 Certificate for PKINIT 2022-12-17T23:55:31Z DEBUG certmonger request is in state 'GENERATING_KEY_PAIR' 2022-12-17T23:55:32Z DEBUG certmonger request is in state 'GENERATING_CSR' 2022-12-17T23:55:32Z DEBUG certmonger request is in state 'SUBMITTING' 2022-12-17T23:55:33Z DEBUG certmonger request is in state 'POST_SAVED_CERT' 2022-12-17T23:55:33Z DEBUG certmonger request is in state 'MONITORING' 2022-12-17T23:55:33Z DEBUG Cert request 20221217235531 was successful 2022-12-17T23:55:34Z DEBUG update_entry modlist [(0, 'ipaconfigstring', [b'pkinitEnabled'])] 2022-12-17T23:55:34Z DEBUG service KDC has all config values set 2022-12-17T23:55:34Z DEBUG step duration: krb5kdc setup_pkinit 2.63 sec 2022-12-17T23:55:34Z DEBUG Done configuring Kerberos KDC (krb5kdc). 2022-12-17T23:55:34Z DEBUG service duration: krb5kdc 2.63 sec 2022-12-17T23:55:34Z DEBUG Starting external process 2022-12-17T23:55:34Z DEBUG args=['/bin/systemctl', 'restart', 'krb5kdc.service'] 2022-12-17T23:55:34Z DEBUG Process finished, return code=0 2022-12-17T23:55:34Z DEBUG stdout= 2022-12-17T23:55:34Z DEBUG stderr= 2022-12-17T23:55:34Z DEBUG Starting external process 2022-12-17T23:55:34Z DEBUG args=['/bin/systemctl', 'is-active', 'krb5kdc.service'] 2022-12-17T23:55:34Z DEBUG Process finished, return code=0 2022-12-17T23:55:34Z DEBUG stdout=active 2022-12-17T23:55:34Z DEBUG stderr= 2022-12-17T23:55:34Z DEBUG Restart of krb5kdc.service complete 2022-12-17T23:55:34Z DEBUG Applying LDAP updates 2022-12-17T23:55:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:34Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:55:34Z DEBUG Starting external process 2022-12-17T23:55:34Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:55:34Z DEBUG Process finished, return code=0 2022-12-17T23:55:34Z DEBUG stdout=active 2022-12-17T23:55:34Z DEBUG stderr= 2022-12-17T23:55:34Z DEBUG Upgrading IPA:. Estimated time: 1 minute 30 seconds 2022-12-17T23:55:34Z DEBUG [1/10]: stopping directory server 2022-12-17T23:55:34Z DEBUG Destroyed connection context.ldap2_140472260056272 2022-12-17T23:55:34Z DEBUG Starting external process 2022-12-17T23:55:34Z DEBUG args=['/bin/systemctl', 'stop', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:55:35Z DEBUG Process finished, return code=0 2022-12-17T23:55:35Z DEBUG stdout= 2022-12-17T23:55:35Z DEBUG stderr= 2022-12-17T23:55:35Z DEBUG Stop of dirsrv@REDACTED_DOMAIN-COM.service complete 2022-12-17T23:55:35Z DEBUG step duration: dirsrv __stop_instance 1.43 sec 2022-12-17T23:55:35Z DEBUG [2/10]: saving configuration 2022-12-17T23:55:35Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:35Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:35Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:35Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:35Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:35Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:35Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:35Z DEBUG step duration: dirsrv __save_config 0.08 sec 2022-12-17T23:55:35Z DEBUG [3/10]: disabling listeners 2022-12-17T23:55:35Z DEBUG step duration: dirsrv __disable_listeners 0.06 sec 2022-12-17T23:55:35Z DEBUG [4/10]: enabling DS global lock 2022-12-17T23:55:35Z DEBUG step duration: dirsrv __enable_ds_global_write_lock 0.06 sec 2022-12-17T23:55:35Z DEBUG [5/10]: disabling Schema Compat 2022-12-17T23:55:35Z DEBUG step duration: dirsrv __disable_schema_compat 0.04 sec 2022-12-17T23:55:35Z DEBUG [6/10]: starting directory server 2022-12-17T23:55:35Z DEBUG Starting external process 2022-12-17T23:55:35Z DEBUG args=['/bin/systemctl', 'start', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:55:37Z DEBUG Process finished, return code=0 2022-12-17T23:55:37Z DEBUG stdout= 2022-12-17T23:55:37Z DEBUG stderr= 2022-12-17T23:55:37Z DEBUG Start of dirsrv@REDACTED_DOMAIN-COM.service complete 2022-12-17T23:55:37Z DEBUG Created connection context.ldap2_140472260056272 2022-12-17T23:55:37Z DEBUG step duration: dirsrv __start 1.83 sec 2022-12-17T23:55:37Z DEBUG [7/10]: upgrading server 2022-12-17T23:55:37Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:55:37Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:55:37Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:55:37Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:55:37Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:55:37Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:55:37Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:55:37Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:55:37Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:55:38Z DEBUG Created connection context.ldap2_140472247965264 2022-12-17T23:55:38Z DEBUG raw: idrange_show('REDACTED_DOMAIN.COM_id_range', version='2.251') 2022-12-17T23:55:38Z DEBUG idrange_show('REDACTED_DOMAIN.COM_id_range', rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:55:38Z DEBUG flushing ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:55:38Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:55:38Z DEBUG Parsing update file '/usr/share/ipa/updates/05-pre_upgrade_plugins.update' 2022-12-17T23:55:38Z DEBUG Executing upgrade plugin: update_managed_post_first 2022-12-17T23:55:38Z DEBUG raw: update_managed_post_first 2022-12-17T23:55:38Z DEBUG Executing upgrade plugin: update_changelog_maxage 2022-12-17T23:55:38Z DEBUG raw: update_changelog_maxage 2022-12-17T23:55:38Z DEBUG Error retrieving: cn=changelog5,cn=config 2022-12-17T23:55:38Z DEBUG Executing upgrade plugin: update_replica_attribute_lists 2022-12-17T23:55:38Z DEBUG raw: update_replica_attribute_lists 2022-12-17T23:55:38Z DEBUG Start replication agreement exclude list update task 2022-12-17T23:55:38Z DEBUG Found 0 agreement(s) 2022-12-17T23:55:38Z DEBUG Done updating agreements 2022-12-17T23:55:38Z DEBUG Executing upgrade plugin: update_passync_privilege_check 2022-12-17T23:55:38Z DEBUG raw: update_passync_privilege_check 2022-12-17T23:55:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:38Z DEBUG Check if there is existing PassSync privilege 2022-12-17T23:55:38Z DEBUG PassSync privilege not found, this is a new update 2022-12-17T23:55:38Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:38Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:38Z DEBUG Executing upgrade plugin: update_referint 2022-12-17T23:55:38Z DEBUG raw: update_referint 2022-12-17T23:55:38Z DEBUG Upgrading referential integrity plugin configuration 2022-12-17T23:55:38Z DEBUG Initial value: LDAPEntry(ipapython.dn.DN('cn=referential integrity postoperation,cn=plugins,cn=config'), {'cn': [b'referential integrity postoperation'], 'nsslapd-plugin-depends-on-type': [b'database'], 'nsslapd-pluginDescription': [b'referential integrity plugin'], 'nsslapd-pluginEnabled': [b'on'], 'nsslapd-pluginId': [b'referint'], 'nsslapd-pluginInitfunc': [b'referint_postop_init'], 'nsslapd-pluginPath': [b'libreferint-plugin'], 'nsslapd-pluginType': [b'betxnpostoperation'], 'nsslapd-pluginVendor': [b'389 Project'], 'nsslapd-pluginVersion': [b'2.2.4'], 'nsslapd-pluginprecedence': [b'40'], 'objectClass': [b'top', b'nsSlapdPlugin', b'extensibleObject'], 'referint-logfile': [b'/var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/referint'], 'referint-membership-attr': [b'member', b'uniquemember', b'owner', b'seeAlso'], 'referint-update-delay': [b'0']}) 2022-12-17T23:55:38Z DEBUG Plugin already uses new style, skipping 2022-12-17T23:55:38Z DEBUG Executing upgrade plugin: update_uniqueness_plugins_to_new_syntax 2022-12-17T23:55:38Z DEBUG raw: update_uniqueness_plugins_to_new_syntax 2022-12-17T23:55:38Z DEBUG No uniqueness plugin entries with old style configuration found 2022-12-17T23:55:38Z DEBUG LDAP update duration: /usr/share/ipa/updates/05-pre_upgrade_plugins.update 0.011 sec 2022-12-17T23:55:38Z DEBUG Parsing update file '/usr/share/ipa/updates/10-config.update' 2022-12-17T23:55:38Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:38Z DEBUG --------------------------------------------- 2022-12-17T23:55:38Z DEBUG Initial value 2022-12-17T23:55:38Z DEBUG dn: cn=config 2022-12-17T23:55:38Z DEBUG cn: 2022-12-17T23:55:38Z DEBUG config 2022-12-17T23:55:38Z DEBUG objectClass: 2022-12-17T23:55:38Z DEBUG top 2022-12-17T23:55:38Z DEBUG extensibleObject 2022-12-17T23:55:38Z DEBUG nsslapdConfig 2022-12-17T23:55:38Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:38Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-betype: 2022-12-17T23:55:38Z DEBUG ldbm database 2022-12-17T23:55:38Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:38Z DEBUG cn=schema 2022-12-17T23:55:38Z DEBUG cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-plugin: 2022-12-17T23:55:38Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 10 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:38Z DEBUG 16384 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-port: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-localuser: 2022-12-17T23:55:38Z DEBUG dirsrv 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG passwordInHistory: 2022-12-17T23:55:38Z DEBUG 6 2022-12-17T23:55:38Z DEBUG passwordUnlock: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG passwordGraceLimit: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG passwordMustChange: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:38Z DEBUG 2000 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG passwordWarning: 2022-12-17T23:55:38Z DEBUG 86400 2022-12-17T23:55:38Z DEBUG nsslapd-readonly: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:38Z DEBUG 16 2022-12-17T23:55:38Z DEBUG passwordLockout: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-localhost: 2022-12-17T23:55:38Z DEBUG master.redacted_domain.com 2022-12-17T23:55:38Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:38Z DEBUG 10000 2022-12-17T23:55:38Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:38Z DEBUG 40 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG passwordMinLength: 2022-12-17T23:55:38Z DEBUG 8 2022-12-17T23:55:38Z DEBUG passwordMinDigits: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinAlphas: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinUppers: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinLowers: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinSpecials: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMin8bit: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinCategories: 2022-12-17T23:55:38Z DEBUG 3 2022-12-17T23:55:38Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:38Z DEBUG 3 2022-12-17T23:55:38Z DEBUG passwordPalindrome: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordDictCheck: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordDictPath: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordUserAttributes: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordBadWords: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordMaxSequence: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:38Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:38Z DEBUG replication-only 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 500 2022-12-17T23:55:38Z DEBUG passwordMaxFailure: 2022-12-17T23:55:38Z DEBUG 3 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:38Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-security: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordMaxAge: 2022-12-17T23:55:38Z DEBUG 8640000 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 2 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:38Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:38Z DEBUG passwordChange: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:38Z DEBUG 256 2022-12-17T23:55:38Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:38Z DEBUG 256 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG nsslapd-securePort: 2022-12-17T23:55:38Z DEBUG 636 2022-12-17T23:55:38Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:38Z DEBUG 64 2022-12-17T23:55:38Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordExp: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG day 2022-12-17T23:55:38Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-nagle: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:38Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:38Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:38Z DEBUG cn=Directory Manager 2022-12-17T23:55:38Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:38Z DEBUG uidNumber 2022-12-17T23:55:38Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:38Z DEBUG gidNumber 2022-12-17T23:55:38Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:38Z DEBUG dc=example,dc=com 2022-12-17T23:55:38Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:38Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-counters: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 2 2022-12-17T23:55:38Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:38Z DEBUG cn=Directory Manager 2022-12-17T23:55:38Z DEBUG passwordMinAge: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:38Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:38Z DEBUG 209715200 2022-12-17T23:55:38Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:38Z DEBUG 2097152 2022-12-17T23:55:38Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:38Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:38Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:38Z DEBUG 524288 2022-12-17T23:55:38Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:38Z DEBUG 1024 2022-12-17T23:55:38Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:38Z DEBUG allowed 2022-12-17T23:55:38Z DEBUG nsslapd-config: 2022-12-17T23:55:38Z DEBUG cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:38Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:38Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:38Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:38Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:38Z DEBUG /tmp 2022-12-17T23:55:38Z DEBUG nsslapd-certdir: 2022-12-17T23:55:38Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:38Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:38Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:38Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:38Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-rundir: 2022-12-17T23:55:38Z DEBUG /run/dirsrv 2022-12-17T23:55:38Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:38Z DEBUG 300000 2022-12-17T23:55:38Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-localssf: 2022-12-17T23:55:38Z DEBUG 71 2022-12-17T23:55:38Z DEBUG nsslapd-minssf: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:38Z DEBUG next 2022-12-17T23:55:38Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:38Z DEBUG warn 2022-12-17T23:55:38Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:38Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:38Z DEBUG 2097152 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:38Z DEBUG 60 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:38Z DEBUG 20971520 2022-12-17T23:55:38Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:38Z DEBUG nolog 2022-12-17T23:55:38Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:38Z DEBUG 2097152 2022-12-17T23:55:38Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:38Z DEBUG 128 2022-12-17T23:55:38Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:38Z DEBUG -10 2022-12-17T23:55:38Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:38Z DEBUG -10 2022-12-17T23:55:38Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:38Z DEBUG -10 2022-12-17T23:55:38Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 2 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 500 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 10 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:38Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:38Z DEBUG dirsrv-log 2022-12-17T23:55:38Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:38Z DEBUG none 2022-12-17T23:55:38Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:38Z DEBUG process-safe 2022-12-17T23:55:38Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:38Z DEBUG 30 2022-12-17T23:55:38Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:38Z DEBUG 300 2022-12-17T23:55:38Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG passwordStorageScheme: 2022-12-17T23:55:38Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:38Z DEBUG passwordAdminDN: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:38Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:38Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:38Z DEBUG aci: 2022-12-17T23:55:38Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:38Z DEBUG only: set nsslapd-ssl-check-hostname to 'on', current value ['on'] 2022-12-17T23:55:38Z DEBUG only: updated value ['on'] 2022-12-17T23:55:38Z DEBUG --------------------------------------------- 2022-12-17T23:55:38Z DEBUG Final value after applying updates 2022-12-17T23:55:38Z DEBUG dn: cn=config 2022-12-17T23:55:38Z DEBUG cn: 2022-12-17T23:55:38Z DEBUG config 2022-12-17T23:55:38Z DEBUG objectClass: 2022-12-17T23:55:38Z DEBUG top 2022-12-17T23:55:38Z DEBUG extensibleObject 2022-12-17T23:55:38Z DEBUG nsslapdConfig 2022-12-17T23:55:38Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:38Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-betype: 2022-12-17T23:55:38Z DEBUG ldbm database 2022-12-17T23:55:38Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:38Z DEBUG cn=schema 2022-12-17T23:55:38Z DEBUG cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-plugin: 2022-12-17T23:55:38Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 10 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:38Z DEBUG 16384 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-port: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-localuser: 2022-12-17T23:55:38Z DEBUG dirsrv 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG passwordInHistory: 2022-12-17T23:55:38Z DEBUG 6 2022-12-17T23:55:38Z DEBUG passwordUnlock: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG passwordGraceLimit: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG passwordMustChange: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:38Z DEBUG 2000 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG passwordWarning: 2022-12-17T23:55:38Z DEBUG 86400 2022-12-17T23:55:38Z DEBUG nsslapd-readonly: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:38Z DEBUG 16 2022-12-17T23:55:38Z DEBUG passwordLockout: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-localhost: 2022-12-17T23:55:38Z DEBUG master.redacted_domain.com 2022-12-17T23:55:38Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:38Z DEBUG 10000 2022-12-17T23:55:38Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:38Z DEBUG 40 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG passwordMinLength: 2022-12-17T23:55:38Z DEBUG 8 2022-12-17T23:55:38Z DEBUG passwordMinDigits: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinAlphas: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinUppers: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinLowers: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinSpecials: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMin8bit: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinCategories: 2022-12-17T23:55:38Z DEBUG 3 2022-12-17T23:55:38Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:38Z DEBUG 3 2022-12-17T23:55:38Z DEBUG passwordPalindrome: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordDictCheck: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordDictPath: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordUserAttributes: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordBadWords: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordMaxSequence: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:38Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:38Z DEBUG replication-only 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 500 2022-12-17T23:55:38Z DEBUG passwordMaxFailure: 2022-12-17T23:55:38Z DEBUG 3 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:38Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-security: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordMaxAge: 2022-12-17T23:55:38Z DEBUG 8640000 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 2 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:38Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:38Z DEBUG passwordChange: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:38Z DEBUG 256 2022-12-17T23:55:38Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:38Z DEBUG 256 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG nsslapd-securePort: 2022-12-17T23:55:38Z DEBUG 636 2022-12-17T23:55:38Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:38Z DEBUG 64 2022-12-17T23:55:38Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordExp: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG day 2022-12-17T23:55:38Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-nagle: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:38Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:38Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:38Z DEBUG cn=Directory Manager 2022-12-17T23:55:38Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:38Z DEBUG uidNumber 2022-12-17T23:55:38Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:38Z DEBUG gidNumber 2022-12-17T23:55:38Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:38Z DEBUG dc=example,dc=com 2022-12-17T23:55:38Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:38Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-counters: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 2 2022-12-17T23:55:38Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:38Z DEBUG cn=Directory Manager 2022-12-17T23:55:38Z DEBUG passwordMinAge: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:38Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:38Z DEBUG 209715200 2022-12-17T23:55:38Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:38Z DEBUG 2097152 2022-12-17T23:55:38Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:38Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:38Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:38Z DEBUG 524288 2022-12-17T23:55:38Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:38Z DEBUG 1024 2022-12-17T23:55:38Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:38Z DEBUG allowed 2022-12-17T23:55:38Z DEBUG nsslapd-config: 2022-12-17T23:55:38Z DEBUG cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:38Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:38Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:38Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:38Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:38Z DEBUG /tmp 2022-12-17T23:55:38Z DEBUG nsslapd-certdir: 2022-12-17T23:55:38Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:38Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:38Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:38Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:38Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-rundir: 2022-12-17T23:55:38Z DEBUG /run/dirsrv 2022-12-17T23:55:38Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:38Z DEBUG 300000 2022-12-17T23:55:38Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-localssf: 2022-12-17T23:55:38Z DEBUG 71 2022-12-17T23:55:38Z DEBUG nsslapd-minssf: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:38Z DEBUG next 2022-12-17T23:55:38Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:38Z DEBUG warn 2022-12-17T23:55:38Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:38Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:38Z DEBUG 2097152 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:38Z DEBUG 60 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:38Z DEBUG 20971520 2022-12-17T23:55:38Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:38Z DEBUG nolog 2022-12-17T23:55:38Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:38Z DEBUG 2097152 2022-12-17T23:55:38Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:38Z DEBUG 128 2022-12-17T23:55:38Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:38Z DEBUG -10 2022-12-17T23:55:38Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:38Z DEBUG -10 2022-12-17T23:55:38Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:38Z DEBUG -10 2022-12-17T23:55:38Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 2 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 500 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 10 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:38Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:38Z DEBUG dirsrv-log 2022-12-17T23:55:38Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:38Z DEBUG none 2022-12-17T23:55:38Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:38Z DEBUG process-safe 2022-12-17T23:55:38Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:38Z DEBUG 30 2022-12-17T23:55:38Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:38Z DEBUG 300 2022-12-17T23:55:38Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG passwordStorageScheme: 2022-12-17T23:55:38Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:38Z DEBUG passwordAdminDN: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:38Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:38Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:38Z DEBUG aci: 2022-12-17T23:55:38Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:38Z DEBUG [] 2022-12-17T23:55:38Z DEBUG Updated 0 2022-12-17T23:55:38Z DEBUG Done 2022-12-17T23:55:38Z DEBUG Updating existing entry: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG --------------------------------------------- 2022-12-17T23:55:38Z DEBUG Initial value 2022-12-17T23:55:38Z DEBUG dn: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn: 2022-12-17T23:55:38Z DEBUG Kerberos Principal Name 2022-12-17T23:55:38Z DEBUG ipamodrdnfilter: 2022-12-17T23:55:38Z DEBUG (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) 2022-12-17T23:55:38Z DEBUG ipamodrdnscope: 2022-12-17T23:55:38Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:38Z DEBUG ipamodrdnsourceattr: 2022-12-17T23:55:38Z DEBUG uid 2022-12-17T23:55:38Z DEBUG ipamodrdnsuffix: 2022-12-17T23:55:38Z DEBUG @REDACTED_DOMAIN.COM 2022-12-17T23:55:38Z DEBUG ipamodrdntargetattr: 2022-12-17T23:55:38Z DEBUG krbPrincipalName 2022-12-17T23:55:38Z DEBUG objectClass: 2022-12-17T23:55:38Z DEBUG top 2022-12-17T23:55:38Z DEBUG extensibleObject 2022-12-17T23:55:38Z DEBUG remove: '60' from nsslapd-pluginPrecedence, current value [] 2022-12-17T23:55:38Z DEBUG remove: '60' not in nsslapd-pluginPrecedence 2022-12-17T23:55:38Z DEBUG --------------------------------------------- 2022-12-17T23:55:38Z DEBUG Final value after applying updates 2022-12-17T23:55:38Z DEBUG dn: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn: 2022-12-17T23:55:38Z DEBUG Kerberos Principal Name 2022-12-17T23:55:38Z DEBUG ipamodrdnfilter: 2022-12-17T23:55:38Z DEBUG (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) 2022-12-17T23:55:38Z DEBUG ipamodrdnscope: 2022-12-17T23:55:38Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:38Z DEBUG ipamodrdnsourceattr: 2022-12-17T23:55:38Z DEBUG uid 2022-12-17T23:55:38Z DEBUG ipamodrdnsuffix: 2022-12-17T23:55:38Z DEBUG @REDACTED_DOMAIN.COM 2022-12-17T23:55:38Z DEBUG ipamodrdntargetattr: 2022-12-17T23:55:38Z DEBUG krbPrincipalName 2022-12-17T23:55:38Z DEBUG objectClass: 2022-12-17T23:55:38Z DEBUG top 2022-12-17T23:55:38Z DEBUG extensibleObject 2022-12-17T23:55:38Z DEBUG [] 2022-12-17T23:55:38Z DEBUG Updated 0 2022-12-17T23:55:38Z DEBUG Done 2022-12-17T23:55:38Z DEBUG Updating existing entry: cn=IPA MODRDN,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG --------------------------------------------- 2022-12-17T23:55:38Z DEBUG Initial value 2022-12-17T23:55:38Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn: 2022-12-17T23:55:38Z DEBUG IPA MODRDN 2022-12-17T23:55:38Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:38Z DEBUG database 2022-12-17T23:55:38Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:38Z DEBUG IPA MODRDN plugin 2022-12-17T23:55:38Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:38Z DEBUG IPA MODRDN 2022-12-17T23:55:38Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:38Z DEBUG ipamodrdn_init 2022-12-17T23:55:38Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:38Z DEBUG libipa_modrdn 2022-12-17T23:55:38Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:38Z DEBUG betxnpostoperation 2022-12-17T23:55:38Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:38Z DEBUG Red Hat, Inc. 2022-12-17T23:55:38Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:38Z DEBUG 1.0 2022-12-17T23:55:38Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:38Z DEBUG 60 2022-12-17T23:55:38Z DEBUG objectClass: 2022-12-17T23:55:38Z DEBUG top 2022-12-17T23:55:38Z DEBUG nsSlapdPlugin 2022-12-17T23:55:38Z DEBUG extensibleObject 2022-12-17T23:55:38Z DEBUG only: set nsslapd-pluginPrecedence to '60', current value ['60'] 2022-12-17T23:55:38Z DEBUG only: updated value ['60'] 2022-12-17T23:55:38Z DEBUG --------------------------------------------- 2022-12-17T23:55:38Z DEBUG Final value after applying updates 2022-12-17T23:55:38Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn: 2022-12-17T23:55:38Z DEBUG IPA MODRDN 2022-12-17T23:55:38Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:38Z DEBUG database 2022-12-17T23:55:38Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:38Z DEBUG IPA MODRDN plugin 2022-12-17T23:55:38Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:38Z DEBUG IPA MODRDN 2022-12-17T23:55:38Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:38Z DEBUG ipamodrdn_init 2022-12-17T23:55:38Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:38Z DEBUG libipa_modrdn 2022-12-17T23:55:38Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:38Z DEBUG betxnpostoperation 2022-12-17T23:55:38Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:38Z DEBUG Red Hat, Inc. 2022-12-17T23:55:38Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:38Z DEBUG 1.0 2022-12-17T23:55:38Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:38Z DEBUG 60 2022-12-17T23:55:38Z DEBUG objectClass: 2022-12-17T23:55:38Z DEBUG top 2022-12-17T23:55:38Z DEBUG nsSlapdPlugin 2022-12-17T23:55:38Z DEBUG extensibleObject 2022-12-17T23:55:38Z DEBUG [] 2022-12-17T23:55:38Z DEBUG Updated 0 2022-12-17T23:55:38Z DEBUG Done 2022-12-17T23:55:38Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:38Z DEBUG --------------------------------------------- 2022-12-17T23:55:38Z DEBUG Initial value 2022-12-17T23:55:38Z DEBUG dn: cn=config 2022-12-17T23:55:38Z DEBUG cn: 2022-12-17T23:55:38Z DEBUG config 2022-12-17T23:55:38Z DEBUG objectClass: 2022-12-17T23:55:38Z DEBUG top 2022-12-17T23:55:38Z DEBUG extensibleObject 2022-12-17T23:55:38Z DEBUG nsslapdConfig 2022-12-17T23:55:38Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:38Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-betype: 2022-12-17T23:55:38Z DEBUG ldbm database 2022-12-17T23:55:38Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:38Z DEBUG cn=schema 2022-12-17T23:55:38Z DEBUG cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-plugin: 2022-12-17T23:55:38Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 10 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:38Z DEBUG 16384 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-port: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-localuser: 2022-12-17T23:55:38Z DEBUG dirsrv 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG passwordInHistory: 2022-12-17T23:55:38Z DEBUG 6 2022-12-17T23:55:38Z DEBUG passwordUnlock: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG passwordGraceLimit: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG passwordMustChange: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:38Z DEBUG 2000 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG passwordWarning: 2022-12-17T23:55:38Z DEBUG 86400 2022-12-17T23:55:38Z DEBUG nsslapd-readonly: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:38Z DEBUG 16 2022-12-17T23:55:38Z DEBUG passwordLockout: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-localhost: 2022-12-17T23:55:38Z DEBUG master.redacted_domain.com 2022-12-17T23:55:38Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:38Z DEBUG 10000 2022-12-17T23:55:38Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:38Z DEBUG 40 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG passwordMinLength: 2022-12-17T23:55:38Z DEBUG 8 2022-12-17T23:55:38Z DEBUG passwordMinDigits: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinAlphas: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinUppers: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinLowers: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinSpecials: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMin8bit: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinCategories: 2022-12-17T23:55:38Z DEBUG 3 2022-12-17T23:55:38Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:38Z DEBUG 3 2022-12-17T23:55:38Z DEBUG passwordPalindrome: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordDictCheck: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordDictPath: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordUserAttributes: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordBadWords: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordMaxSequence: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:38Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:38Z DEBUG replication-only 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 500 2022-12-17T23:55:38Z DEBUG passwordMaxFailure: 2022-12-17T23:55:38Z DEBUG 3 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:38Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-security: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordMaxAge: 2022-12-17T23:55:38Z DEBUG 8640000 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 2 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:38Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:38Z DEBUG passwordChange: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:38Z DEBUG 256 2022-12-17T23:55:38Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:38Z DEBUG 256 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG nsslapd-securePort: 2022-12-17T23:55:38Z DEBUG 636 2022-12-17T23:55:38Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:38Z DEBUG 64 2022-12-17T23:55:38Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordExp: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG day 2022-12-17T23:55:38Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-nagle: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:38Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:38Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:38Z DEBUG cn=Directory Manager 2022-12-17T23:55:38Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:38Z DEBUG uidNumber 2022-12-17T23:55:38Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:38Z DEBUG gidNumber 2022-12-17T23:55:38Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:38Z DEBUG dc=example,dc=com 2022-12-17T23:55:38Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:38Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-counters: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 2 2022-12-17T23:55:38Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:38Z DEBUG cn=Directory Manager 2022-12-17T23:55:38Z DEBUG passwordMinAge: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:38Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:38Z DEBUG 209715200 2022-12-17T23:55:38Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:38Z DEBUG 2097152 2022-12-17T23:55:38Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:38Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:38Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:38Z DEBUG 524288 2022-12-17T23:55:38Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:38Z DEBUG 1024 2022-12-17T23:55:38Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:38Z DEBUG allowed 2022-12-17T23:55:38Z DEBUG nsslapd-config: 2022-12-17T23:55:38Z DEBUG cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:38Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:38Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:38Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:38Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:38Z DEBUG /tmp 2022-12-17T23:55:38Z DEBUG nsslapd-certdir: 2022-12-17T23:55:38Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:38Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:38Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:38Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:38Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-rundir: 2022-12-17T23:55:38Z DEBUG /run/dirsrv 2022-12-17T23:55:38Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:38Z DEBUG 300000 2022-12-17T23:55:38Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-localssf: 2022-12-17T23:55:38Z DEBUG 71 2022-12-17T23:55:38Z DEBUG nsslapd-minssf: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:38Z DEBUG next 2022-12-17T23:55:38Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:38Z DEBUG warn 2022-12-17T23:55:38Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:38Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:38Z DEBUG 2097152 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:38Z DEBUG 60 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:38Z DEBUG 20971520 2022-12-17T23:55:38Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:38Z DEBUG nolog 2022-12-17T23:55:38Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:38Z DEBUG 2097152 2022-12-17T23:55:38Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:38Z DEBUG 128 2022-12-17T23:55:38Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:38Z DEBUG -10 2022-12-17T23:55:38Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:38Z DEBUG -10 2022-12-17T23:55:38Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:38Z DEBUG -10 2022-12-17T23:55:38Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 2 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 500 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 10 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:38Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:38Z DEBUG dirsrv-log 2022-12-17T23:55:38Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:38Z DEBUG none 2022-12-17T23:55:38Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:38Z DEBUG process-safe 2022-12-17T23:55:38Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:38Z DEBUG 30 2022-12-17T23:55:38Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:38Z DEBUG 300 2022-12-17T23:55:38Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG passwordStorageScheme: 2022-12-17T23:55:38Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:38Z DEBUG passwordAdminDN: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:38Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:38Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:38Z DEBUG aci: 2022-12-17T23:55:38Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:38Z DEBUG replace: updated value ['100000'] 2022-12-17T23:55:38Z DEBUG --------------------------------------------- 2022-12-17T23:55:38Z DEBUG Final value after applying updates 2022-12-17T23:55:38Z DEBUG dn: cn=config 2022-12-17T23:55:38Z DEBUG cn: 2022-12-17T23:55:38Z DEBUG config 2022-12-17T23:55:38Z DEBUG objectClass: 2022-12-17T23:55:38Z DEBUG top 2022-12-17T23:55:38Z DEBUG extensibleObject 2022-12-17T23:55:38Z DEBUG nsslapdConfig 2022-12-17T23:55:38Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:38Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-betype: 2022-12-17T23:55:38Z DEBUG ldbm database 2022-12-17T23:55:38Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:38Z DEBUG cn=schema 2022-12-17T23:55:38Z DEBUG cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-plugin: 2022-12-17T23:55:38Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:38Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:38Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:38Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 10 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:38Z DEBUG 16384 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-port: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-localuser: 2022-12-17T23:55:38Z DEBUG dirsrv 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG passwordInHistory: 2022-12-17T23:55:38Z DEBUG 6 2022-12-17T23:55:38Z DEBUG passwordUnlock: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG passwordGraceLimit: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG passwordMustChange: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:38Z DEBUG 100000 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG passwordWarning: 2022-12-17T23:55:38Z DEBUG 86400 2022-12-17T23:55:38Z DEBUG nsslapd-readonly: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:38Z DEBUG 16 2022-12-17T23:55:38Z DEBUG passwordLockout: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-localhost: 2022-12-17T23:55:38Z DEBUG master.redacted_domain.com 2022-12-17T23:55:38Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:38Z DEBUG 10000 2022-12-17T23:55:38Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:38Z DEBUG 40 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG passwordMinLength: 2022-12-17T23:55:38Z DEBUG 8 2022-12-17T23:55:38Z DEBUG passwordMinDigits: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinAlphas: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinUppers: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinLowers: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinSpecials: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMin8bit: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMinCategories: 2022-12-17T23:55:38Z DEBUG 3 2022-12-17T23:55:38Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:38Z DEBUG 3 2022-12-17T23:55:38Z DEBUG passwordPalindrome: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordDictCheck: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordDictPath: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordUserAttributes: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordBadWords: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordMaxSequence: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:38Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:38Z DEBUG replication-only 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 500 2022-12-17T23:55:38Z DEBUG passwordMaxFailure: 2022-12-17T23:55:38Z DEBUG 3 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:38Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-security: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordMaxAge: 2022-12-17T23:55:38Z DEBUG 8640000 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 2 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:38Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:38Z DEBUG passwordChange: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:38Z DEBUG 256 2022-12-17T23:55:38Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:38Z DEBUG 256 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG nsslapd-securePort: 2022-12-17T23:55:38Z DEBUG 636 2022-12-17T23:55:38Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:38Z DEBUG 64 2022-12-17T23:55:38Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG passwordExp: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG day 2022-12-17T23:55:38Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-nagle: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:38Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:38Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:38Z DEBUG cn=Directory Manager 2022-12-17T23:55:38Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:38Z DEBUG uidNumber 2022-12-17T23:55:38Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:38Z DEBUG gidNumber 2022-12-17T23:55:38Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:38Z DEBUG dc=example,dc=com 2022-12-17T23:55:38Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:38Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-counters: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 2 2022-12-17T23:55:38Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:38Z DEBUG cn=Directory Manager 2022-12-17T23:55:38Z DEBUG passwordMinAge: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:38Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:38Z DEBUG 209715200 2022-12-17T23:55:38Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:38Z DEBUG 2097152 2022-12-17T23:55:38Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:38Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:38Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:38Z DEBUG 524288 2022-12-17T23:55:38Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:38Z DEBUG 1024 2022-12-17T23:55:38Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:38Z DEBUG allowed 2022-12-17T23:55:38Z DEBUG nsslapd-config: 2022-12-17T23:55:38Z DEBUG cn=config 2022-12-17T23:55:38Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:38Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:38Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:38Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:38Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:38Z DEBUG /tmp 2022-12-17T23:55:38Z DEBUG nsslapd-certdir: 2022-12-17T23:55:38Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:38Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:38Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:38Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:38Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:38Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-rundir: 2022-12-17T23:55:38Z DEBUG /run/dirsrv 2022-12-17T23:55:38Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:38Z DEBUG 300000 2022-12-17T23:55:38Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-localssf: 2022-12-17T23:55:38Z DEBUG 71 2022-12-17T23:55:38Z DEBUG nsslapd-minssf: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:38Z DEBUG next 2022-12-17T23:55:38Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:38Z DEBUG warn 2022-12-17T23:55:38Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:38Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:38Z DEBUG 2097152 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:38Z DEBUG 60 2022-12-17T23:55:38Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:38Z DEBUG 20971520 2022-12-17T23:55:38Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:38Z DEBUG nolog 2022-12-17T23:55:38Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:38Z DEBUG 2097152 2022-12-17T23:55:38Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:38Z DEBUG 128 2022-12-17T23:55:38Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:38Z DEBUG -10 2022-12-17T23:55:38Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:38Z DEBUG -10 2022-12-17T23:55:38Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:38Z DEBUG -10 2022-12-17T23:55:38Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:38Z DEBUG -1 2022-12-17T23:55:38Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 2 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:38Z DEBUG 600 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:38Z DEBUG 0 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:38Z DEBUG 500 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:38Z DEBUG 100 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:38Z DEBUG 1 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:38Z DEBUG 10 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:38Z DEBUG month 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:38Z DEBUG 5 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:38Z DEBUG week 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:38Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:38Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:38Z DEBUG dirsrv-log 2022-12-17T23:55:38Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:38Z DEBUG none 2022-12-17T23:55:38Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:38Z DEBUG process-safe 2022-12-17T23:55:38Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:38Z DEBUG 3600 2022-12-17T23:55:38Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:38Z DEBUG 30 2022-12-17T23:55:38Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:38Z DEBUG 300 2022-12-17T23:55:38Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG passwordStorageScheme: 2022-12-17T23:55:38Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:38Z DEBUG passwordAdminDN: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:38Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:38Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:38Z DEBUG on 2022-12-17T23:55:38Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:38Z DEBUG off 2022-12-17T23:55:38Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:38Z DEBUG 2022-12-17T23:55:38Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:38Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:38Z DEBUG aci: 2022-12-17T23:55:38Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:38Z DEBUG [(2, 'nsslapd-sizelimit', ['100000'])] 2022-12-17T23:55:38Z DEBUG Updated 1 2022-12-17T23:55:38Z DEBUG update_entry modlist [(2, 'nsslapd-sizelimit', [b'100000'])] 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=config,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapd-lookthroughlimit: 2022-12-17T23:55:39Z DEBUG 5000 2022-12-17T23:55:39Z DEBUG nsslapd-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-idlistscanlimit: 2022-12-17T23:55:39Z DEBUG 4000 2022-12-17T23:55:39Z DEBUG nsslapd-directory: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/db 2022-12-17T23:55:39Z DEBUG nsslapd-import-cachesize: 2022-12-17T23:55:39Z DEBUG 16777216 2022-12-17T23:55:39Z DEBUG nsslapd-idl-switch: 2022-12-17T23:55:39Z DEBUG new 2022-12-17T23:55:39Z DEBUG nsslapd-search-bypass-filter-test: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-search-use-vlv-index: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-exclude-from-export: 2022-12-17T23:55:39Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2022-12-17T23:55:39Z DEBUG nsslapd-serial-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-subtree-rename-switch: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pagedlookthroughlimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-pagedidlistscanlimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-rangelookthroughlimit: 2022-12-17T23:55:39Z DEBUG 5000 2022-12-17T23:55:39Z DEBUG nsslapd-backend-opt-level: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-backend-implement: 2022-12-17T23:55:39Z DEBUG bdb 2022-12-17T23:55:39Z DEBUG replace: updated value ['100000'] 2022-12-17T23:55:39Z DEBUG replace: updated value ['100000'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapd-lookthroughlimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-idlistscanlimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-directory: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/db 2022-12-17T23:55:39Z DEBUG nsslapd-import-cachesize: 2022-12-17T23:55:39Z DEBUG 16777216 2022-12-17T23:55:39Z DEBUG nsslapd-idl-switch: 2022-12-17T23:55:39Z DEBUG new 2022-12-17T23:55:39Z DEBUG nsslapd-search-bypass-filter-test: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-search-use-vlv-index: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-exclude-from-export: 2022-12-17T23:55:39Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2022-12-17T23:55:39Z DEBUG nsslapd-serial-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-subtree-rename-switch: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pagedlookthroughlimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-pagedidlistscanlimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-rangelookthroughlimit: 2022-12-17T23:55:39Z DEBUG 5000 2022-12-17T23:55:39Z DEBUG nsslapd-backend-opt-level: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-backend-implement: 2022-12-17T23:55:39Z DEBUG bdb 2022-12-17T23:55:39Z DEBUG [(2, 'nsslapd-lookthroughlimit', ['100000']), (2, 'nsslapd-idlistscanlimit', ['100000'])] 2022-12-17T23:55:39Z DEBUG Updated 1 2022-12-17T23:55:39Z DEBUG update_entry modlist [(2, 'nsslapd-lookthroughlimit', [b'100000']), (2, 'nsslapd-idlistscanlimit', [b'100000'])] 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG New entry: cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG objectclass: 2022-12-17T23:55:39Z DEBUG nsContainer 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG anonymous-limits 2022-12-17T23:55:39Z DEBUG nsSizeLimit: 2022-12-17T23:55:39Z DEBUG 5000 2022-12-17T23:55:39Z DEBUG nsLookThroughLimit: 2022-12-17T23:55:39Z DEBUG 5000 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG objectclass: 2022-12-17T23:55:39Z DEBUG nsContainer 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG anonymous-limits 2022-12-17T23:55:39Z DEBUG nsSizeLimit: 2022-12-17T23:55:39Z DEBUG 5000 2022-12-17T23:55:39Z DEBUG nsLookThroughLimit: 2022-12-17T23:55:39Z DEBUG 5000 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapdConfig 2022-12-17T23:55:39Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:39Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-betype: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:39Z DEBUG cn=schema 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-plugin: 2022-12-17T23:55:39Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:39Z DEBUG 16384 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-port: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-localuser: 2022-12-17T23:55:39Z DEBUG dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordInHistory: 2022-12-17T23:55:39Z DEBUG 6 2022-12-17T23:55:39Z DEBUG passwordUnlock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordGraceLimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordMustChange: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordWarning: 2022-12-17T23:55:39Z DEBUG 86400 2022-12-17T23:55:39Z DEBUG nsslapd-readonly: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:39Z DEBUG 16 2022-12-17T23:55:39Z DEBUG passwordLockout: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-localhost: 2022-12-17T23:55:39Z DEBUG master.redacted_domain.com 2022-12-17T23:55:39Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:39Z DEBUG 10000 2022-12-17T23:55:39Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordMinLength: 2022-12-17T23:55:39Z DEBUG 8 2022-12-17T23:55:39Z DEBUG passwordMinDigits: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinAlphas: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinUppers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinLowers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinSpecials: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMin8bit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinCategories: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordPalindrome: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictCheck: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictPath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordUserAttributes: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordBadWords: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordMaxSequence: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:39Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:39Z DEBUG replication-only 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG passwordMaxFailure: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:39Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-security: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordMaxAge: 2022-12-17T23:55:39Z DEBUG 8640000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:39Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:39Z DEBUG passwordChange: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securePort: 2022-12-17T23:55:39Z DEBUG 636 2022-12-17T23:55:39Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:39Z DEBUG 64 2022-12-17T23:55:39Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordExp: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG day 2022-12-17T23:55:39Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-nagle: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:39Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:39Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:39Z DEBUG uidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:39Z DEBUG gidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:39Z DEBUG dc=example,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:39Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-counters: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG passwordMinAge: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:39Z DEBUG 209715200 2022-12-17T23:55:39Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:39Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:39Z DEBUG 524288 2022-12-17T23:55:39Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:39Z DEBUG 1024 2022-12-17T23:55:39Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:39Z DEBUG allowed 2022-12-17T23:55:39Z DEBUG nsslapd-config: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:39Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:39Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:39Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:39Z DEBUG /tmp 2022-12-17T23:55:39Z DEBUG nsslapd-certdir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:39Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:39Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rundir: 2022-12-17T23:55:39Z DEBUG /run/dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:39Z DEBUG 300000 2022-12-17T23:55:39Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-localssf: 2022-12-17T23:55:39Z DEBUG 71 2022-12-17T23:55:39Z DEBUG nsslapd-minssf: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:39Z DEBUG next 2022-12-17T23:55:39Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:39Z DEBUG warn 2022-12-17T23:55:39Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:39Z DEBUG 20971520 2022-12-17T23:55:39Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:39Z DEBUG nolog 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:39Z DEBUG 128 2022-12-17T23:55:39Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:39Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:39Z DEBUG dirsrv-log 2022-12-17T23:55:39Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:39Z DEBUG process-safe 2022-12-17T23:55:39Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:39Z DEBUG 30 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:39Z DEBUG 300 2022-12-17T23:55:39Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordStorageScheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG passwordAdminDN: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:39Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:39Z DEBUG only: set nsslapd-anonlimitsdn to 'cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com', current value [''] 2022-12-17T23:55:39Z DEBUG only: updated value ['cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapdConfig 2022-12-17T23:55:39Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:39Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-betype: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:39Z DEBUG cn=schema 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-plugin: 2022-12-17T23:55:39Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:39Z DEBUG 16384 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-port: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-localuser: 2022-12-17T23:55:39Z DEBUG dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordInHistory: 2022-12-17T23:55:39Z DEBUG 6 2022-12-17T23:55:39Z DEBUG passwordUnlock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordGraceLimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordMustChange: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordWarning: 2022-12-17T23:55:39Z DEBUG 86400 2022-12-17T23:55:39Z DEBUG nsslapd-readonly: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:39Z DEBUG 16 2022-12-17T23:55:39Z DEBUG passwordLockout: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-localhost: 2022-12-17T23:55:39Z DEBUG master.redacted_domain.com 2022-12-17T23:55:39Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:39Z DEBUG 10000 2022-12-17T23:55:39Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordMinLength: 2022-12-17T23:55:39Z DEBUG 8 2022-12-17T23:55:39Z DEBUG passwordMinDigits: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinAlphas: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinUppers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinLowers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinSpecials: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMin8bit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinCategories: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordPalindrome: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictCheck: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictPath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordUserAttributes: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordBadWords: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordMaxSequence: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:39Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:39Z DEBUG replication-only 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG passwordMaxFailure: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:39Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-security: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordMaxAge: 2022-12-17T23:55:39Z DEBUG 8640000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:39Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:39Z DEBUG passwordChange: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securePort: 2022-12-17T23:55:39Z DEBUG 636 2022-12-17T23:55:39Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:39Z DEBUG 64 2022-12-17T23:55:39Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordExp: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG day 2022-12-17T23:55:39Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-nagle: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:39Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:39Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:39Z DEBUG uidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:39Z DEBUG gidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:39Z DEBUG dc=example,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:39Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:39Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-counters: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG passwordMinAge: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:39Z DEBUG 209715200 2022-12-17T23:55:39Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:39Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:39Z DEBUG 524288 2022-12-17T23:55:39Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:39Z DEBUG 1024 2022-12-17T23:55:39Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:39Z DEBUG allowed 2022-12-17T23:55:39Z DEBUG nsslapd-config: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:39Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:39Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:39Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:39Z DEBUG /tmp 2022-12-17T23:55:39Z DEBUG nsslapd-certdir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:39Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:39Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rundir: 2022-12-17T23:55:39Z DEBUG /run/dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:39Z DEBUG 300000 2022-12-17T23:55:39Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-localssf: 2022-12-17T23:55:39Z DEBUG 71 2022-12-17T23:55:39Z DEBUG nsslapd-minssf: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:39Z DEBUG next 2022-12-17T23:55:39Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:39Z DEBUG warn 2022-12-17T23:55:39Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:39Z DEBUG 20971520 2022-12-17T23:55:39Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:39Z DEBUG nolog 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:39Z DEBUG 128 2022-12-17T23:55:39Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:39Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:39Z DEBUG dirsrv-log 2022-12-17T23:55:39Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:39Z DEBUG process-safe 2022-12-17T23:55:39Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:39Z DEBUG 30 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:39Z DEBUG 300 2022-12-17T23:55:39Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordStorageScheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG passwordAdminDN: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:39Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:39Z DEBUG [(2, 'nsslapd-anonlimitsdn', ['cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:39Z DEBUG Updated 1 2022-12-17T23:55:39Z DEBUG update_entry modlist [(2, 'nsslapd-anonlimitsdn', [b'cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapdConfig 2022-12-17T23:55:39Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:39Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-betype: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:39Z DEBUG cn=schema 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-plugin: 2022-12-17T23:55:39Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:39Z DEBUG 16384 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-port: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-localuser: 2022-12-17T23:55:39Z DEBUG dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordInHistory: 2022-12-17T23:55:39Z DEBUG 6 2022-12-17T23:55:39Z DEBUG passwordUnlock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordGraceLimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordMustChange: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordWarning: 2022-12-17T23:55:39Z DEBUG 86400 2022-12-17T23:55:39Z DEBUG nsslapd-readonly: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:39Z DEBUG 16 2022-12-17T23:55:39Z DEBUG passwordLockout: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-localhost: 2022-12-17T23:55:39Z DEBUG master.redacted_domain.com 2022-12-17T23:55:39Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:39Z DEBUG 10000 2022-12-17T23:55:39Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordMinLength: 2022-12-17T23:55:39Z DEBUG 8 2022-12-17T23:55:39Z DEBUG passwordMinDigits: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinAlphas: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinUppers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinLowers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinSpecials: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMin8bit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinCategories: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordPalindrome: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictCheck: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictPath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordUserAttributes: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordBadWords: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordMaxSequence: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:39Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:39Z DEBUG replication-only 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG passwordMaxFailure: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:39Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-security: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordMaxAge: 2022-12-17T23:55:39Z DEBUG 8640000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:39Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:39Z DEBUG passwordChange: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securePort: 2022-12-17T23:55:39Z DEBUG 636 2022-12-17T23:55:39Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:39Z DEBUG 64 2022-12-17T23:55:39Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordExp: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG day 2022-12-17T23:55:39Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-nagle: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:39Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:39Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:39Z DEBUG uidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:39Z DEBUG gidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:39Z DEBUG dc=example,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:39Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:39Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-counters: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG passwordMinAge: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:39Z DEBUG 209715200 2022-12-17T23:55:39Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:39Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:39Z DEBUG 524288 2022-12-17T23:55:39Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:39Z DEBUG 1024 2022-12-17T23:55:39Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:39Z DEBUG allowed 2022-12-17T23:55:39Z DEBUG nsslapd-config: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:39Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:39Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:39Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:39Z DEBUG /tmp 2022-12-17T23:55:39Z DEBUG nsslapd-certdir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:39Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:39Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rundir: 2022-12-17T23:55:39Z DEBUG /run/dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:39Z DEBUG 300000 2022-12-17T23:55:39Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-localssf: 2022-12-17T23:55:39Z DEBUG 71 2022-12-17T23:55:39Z DEBUG nsslapd-minssf: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:39Z DEBUG next 2022-12-17T23:55:39Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:39Z DEBUG warn 2022-12-17T23:55:39Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:39Z DEBUG 20971520 2022-12-17T23:55:39Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:39Z DEBUG nolog 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:39Z DEBUG 128 2022-12-17T23:55:39Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:39Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:39Z DEBUG dirsrv-log 2022-12-17T23:55:39Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:39Z DEBUG process-safe 2022-12-17T23:55:39Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:39Z DEBUG 30 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:39Z DEBUG 300 2022-12-17T23:55:39Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordStorageScheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG passwordAdminDN: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:39Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:39Z DEBUG add: 'dc=redacted_domain,dc=com' to nsslapd-defaultNamingContext, current value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:39Z DEBUG add: updated value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapdConfig 2022-12-17T23:55:39Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:39Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-betype: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:39Z DEBUG cn=schema 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-plugin: 2022-12-17T23:55:39Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:39Z DEBUG 16384 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-port: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-localuser: 2022-12-17T23:55:39Z DEBUG dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordInHistory: 2022-12-17T23:55:39Z DEBUG 6 2022-12-17T23:55:39Z DEBUG passwordUnlock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordGraceLimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordMustChange: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordWarning: 2022-12-17T23:55:39Z DEBUG 86400 2022-12-17T23:55:39Z DEBUG nsslapd-readonly: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:39Z DEBUG 16 2022-12-17T23:55:39Z DEBUG passwordLockout: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-localhost: 2022-12-17T23:55:39Z DEBUG master.redacted_domain.com 2022-12-17T23:55:39Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:39Z DEBUG 10000 2022-12-17T23:55:39Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordMinLength: 2022-12-17T23:55:39Z DEBUG 8 2022-12-17T23:55:39Z DEBUG passwordMinDigits: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinAlphas: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinUppers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinLowers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinSpecials: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMin8bit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinCategories: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordPalindrome: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictCheck: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictPath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordUserAttributes: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordBadWords: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordMaxSequence: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:39Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:39Z DEBUG replication-only 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG passwordMaxFailure: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:39Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-security: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordMaxAge: 2022-12-17T23:55:39Z DEBUG 8640000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:39Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:39Z DEBUG passwordChange: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securePort: 2022-12-17T23:55:39Z DEBUG 636 2022-12-17T23:55:39Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:39Z DEBUG 64 2022-12-17T23:55:39Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordExp: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG day 2022-12-17T23:55:39Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-nagle: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:39Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:39Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:39Z DEBUG uidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:39Z DEBUG gidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:39Z DEBUG dc=example,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:39Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:39Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-counters: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG passwordMinAge: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:39Z DEBUG 209715200 2022-12-17T23:55:39Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:39Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:39Z DEBUG 524288 2022-12-17T23:55:39Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:39Z DEBUG 1024 2022-12-17T23:55:39Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:39Z DEBUG allowed 2022-12-17T23:55:39Z DEBUG nsslapd-config: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:39Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:39Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:39Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:39Z DEBUG /tmp 2022-12-17T23:55:39Z DEBUG nsslapd-certdir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:39Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:39Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rundir: 2022-12-17T23:55:39Z DEBUG /run/dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:39Z DEBUG 300000 2022-12-17T23:55:39Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-localssf: 2022-12-17T23:55:39Z DEBUG 71 2022-12-17T23:55:39Z DEBUG nsslapd-minssf: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:39Z DEBUG next 2022-12-17T23:55:39Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:39Z DEBUG warn 2022-12-17T23:55:39Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:39Z DEBUG 20971520 2022-12-17T23:55:39Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:39Z DEBUG nolog 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:39Z DEBUG 128 2022-12-17T23:55:39Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:39Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:39Z DEBUG dirsrv-log 2022-12-17T23:55:39Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:39Z DEBUG process-safe 2022-12-17T23:55:39Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:39Z DEBUG 30 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:39Z DEBUG 300 2022-12-17T23:55:39Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordStorageScheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG passwordAdminDN: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:39Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapdConfig 2022-12-17T23:55:39Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:39Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-betype: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:39Z DEBUG cn=schema 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-plugin: 2022-12-17T23:55:39Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:39Z DEBUG 16384 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-port: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-localuser: 2022-12-17T23:55:39Z DEBUG dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordInHistory: 2022-12-17T23:55:39Z DEBUG 6 2022-12-17T23:55:39Z DEBUG passwordUnlock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordGraceLimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordMustChange: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordWarning: 2022-12-17T23:55:39Z DEBUG 86400 2022-12-17T23:55:39Z DEBUG nsslapd-readonly: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:39Z DEBUG 16 2022-12-17T23:55:39Z DEBUG passwordLockout: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-localhost: 2022-12-17T23:55:39Z DEBUG master.redacted_domain.com 2022-12-17T23:55:39Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:39Z DEBUG 10000 2022-12-17T23:55:39Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordMinLength: 2022-12-17T23:55:39Z DEBUG 8 2022-12-17T23:55:39Z DEBUG passwordMinDigits: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinAlphas: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinUppers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinLowers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinSpecials: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMin8bit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinCategories: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordPalindrome: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictCheck: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictPath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordUserAttributes: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordBadWords: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordMaxSequence: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:39Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:39Z DEBUG replication-only 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG passwordMaxFailure: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:39Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-security: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordMaxAge: 2022-12-17T23:55:39Z DEBUG 8640000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:39Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:39Z DEBUG passwordChange: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securePort: 2022-12-17T23:55:39Z DEBUG 636 2022-12-17T23:55:39Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:39Z DEBUG 64 2022-12-17T23:55:39Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordExp: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG day 2022-12-17T23:55:39Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-nagle: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:39Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:39Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:39Z DEBUG uidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:39Z DEBUG gidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:39Z DEBUG dc=example,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:39Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:39Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-counters: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG passwordMinAge: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:39Z DEBUG 209715200 2022-12-17T23:55:39Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:39Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:39Z DEBUG 524288 2022-12-17T23:55:39Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:39Z DEBUG 1024 2022-12-17T23:55:39Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:39Z DEBUG allowed 2022-12-17T23:55:39Z DEBUG nsslapd-config: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:39Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:39Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:39Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:39Z DEBUG /tmp 2022-12-17T23:55:39Z DEBUG nsslapd-certdir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:39Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:39Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rundir: 2022-12-17T23:55:39Z DEBUG /run/dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:39Z DEBUG 300000 2022-12-17T23:55:39Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-localssf: 2022-12-17T23:55:39Z DEBUG 71 2022-12-17T23:55:39Z DEBUG nsslapd-minssf: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:39Z DEBUG next 2022-12-17T23:55:39Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:39Z DEBUG warn 2022-12-17T23:55:39Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:39Z DEBUG 20971520 2022-12-17T23:55:39Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:39Z DEBUG nolog 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:39Z DEBUG 128 2022-12-17T23:55:39Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:39Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:39Z DEBUG dirsrv-log 2022-12-17T23:55:39Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:39Z DEBUG process-safe 2022-12-17T23:55:39Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:39Z DEBUG 30 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:39Z DEBUG 300 2022-12-17T23:55:39Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordStorageScheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG passwordAdminDN: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:39Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:39Z DEBUG only: set nsslapd-minssf-exclude-rootdse to 'on', current value ['off'] 2022-12-17T23:55:39Z DEBUG only: updated value ['on'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapdConfig 2022-12-17T23:55:39Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:39Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-betype: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:39Z DEBUG cn=schema 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-plugin: 2022-12-17T23:55:39Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:39Z DEBUG 16384 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-port: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-localuser: 2022-12-17T23:55:39Z DEBUG dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordInHistory: 2022-12-17T23:55:39Z DEBUG 6 2022-12-17T23:55:39Z DEBUG passwordUnlock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordGraceLimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordMustChange: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordWarning: 2022-12-17T23:55:39Z DEBUG 86400 2022-12-17T23:55:39Z DEBUG nsslapd-readonly: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:39Z DEBUG 16 2022-12-17T23:55:39Z DEBUG passwordLockout: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-localhost: 2022-12-17T23:55:39Z DEBUG master.redacted_domain.com 2022-12-17T23:55:39Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:39Z DEBUG 10000 2022-12-17T23:55:39Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordMinLength: 2022-12-17T23:55:39Z DEBUG 8 2022-12-17T23:55:39Z DEBUG passwordMinDigits: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinAlphas: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinUppers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinLowers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinSpecials: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMin8bit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinCategories: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordPalindrome: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictCheck: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictPath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordUserAttributes: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordBadWords: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordMaxSequence: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:39Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:39Z DEBUG replication-only 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG passwordMaxFailure: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:39Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-security: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordMaxAge: 2022-12-17T23:55:39Z DEBUG 8640000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:39Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:39Z DEBUG passwordChange: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securePort: 2022-12-17T23:55:39Z DEBUG 636 2022-12-17T23:55:39Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:39Z DEBUG 64 2022-12-17T23:55:39Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordExp: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG day 2022-12-17T23:55:39Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-nagle: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:39Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:39Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:39Z DEBUG uidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:39Z DEBUG gidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:39Z DEBUG dc=example,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:39Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:39Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-counters: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG passwordMinAge: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:39Z DEBUG 209715200 2022-12-17T23:55:39Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:39Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:39Z DEBUG 524288 2022-12-17T23:55:39Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:39Z DEBUG 1024 2022-12-17T23:55:39Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:39Z DEBUG allowed 2022-12-17T23:55:39Z DEBUG nsslapd-config: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:39Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:39Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:39Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:39Z DEBUG /tmp 2022-12-17T23:55:39Z DEBUG nsslapd-certdir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:39Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:39Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rundir: 2022-12-17T23:55:39Z DEBUG /run/dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:39Z DEBUG 300000 2022-12-17T23:55:39Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-localssf: 2022-12-17T23:55:39Z DEBUG 71 2022-12-17T23:55:39Z DEBUG nsslapd-minssf: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:39Z DEBUG next 2022-12-17T23:55:39Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:39Z DEBUG warn 2022-12-17T23:55:39Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:39Z DEBUG 20971520 2022-12-17T23:55:39Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:39Z DEBUG nolog 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:39Z DEBUG 128 2022-12-17T23:55:39Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:39Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:39Z DEBUG dirsrv-log 2022-12-17T23:55:39Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:39Z DEBUG process-safe 2022-12-17T23:55:39Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:39Z DEBUG 30 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:39Z DEBUG 300 2022-12-17T23:55:39Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordStorageScheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG passwordAdminDN: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:39Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:39Z DEBUG [(2, 'nsslapd-minssf-exclude-rootdse', ['on'])] 2022-12-17T23:55:39Z DEBUG Updated 1 2022-12-17T23:55:39Z DEBUG update_entry modlist [(2, 'nsslapd-minssf-exclude-rootdse', [b'on'])] 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=ipa-winsync,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG ipa-winsync 2022-12-17T23:55:39Z DEBUG ipawinsyncacctdisable: 2022-12-17T23:55:39Z DEBUG both 2022-12-17T23:55:39Z DEBUG ipawinsyncdefaultgroupattr: 2022-12-17T23:55:39Z DEBUG ipaDefaultPrimaryGroup 2022-12-17T23:55:39Z DEBUG ipawinsyncdefaultgroupfilter: 2022-12-17T23:55:39Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2022-12-17T23:55:39Z DEBUG ipawinsyncforcesync: 2022-12-17T23:55:39Z DEBUG true 2022-12-17T23:55:39Z DEBUG ipawinsynchomedirattr: 2022-12-17T23:55:39Z DEBUG ipaHomesRootDir 2022-12-17T23:55:39Z DEBUG ipawinsyncloginshellattr: 2022-12-17T23:55:39Z DEBUG ipaDefaultLoginShell 2022-12-17T23:55:39Z DEBUG ipawinsyncnewentryfilter: 2022-12-17T23:55:39Z DEBUG (cn=ipaConfig) 2022-12-17T23:55:39Z DEBUG ipawinsyncnewuserocattr: 2022-12-17T23:55:39Z DEBUG ipauserobjectclasses 2022-12-17T23:55:39Z DEBUG ipawinsyncrealmattr: 2022-12-17T23:55:39Z DEBUG cn 2022-12-17T23:55:39Z DEBUG ipawinsyncrealmfilter: 2022-12-17T23:55:39Z DEBUG (objectclass=krbRealmContainer) 2022-12-17T23:55:39Z DEBUG ipawinsyncuserattr: 2022-12-17T23:55:39Z DEBUG uidNumber -1 2022-12-17T23:55:39Z DEBUG gidNumber -1 2022-12-17T23:55:39Z DEBUG ipawinsyncuserflatten: 2022-12-17T23:55:39Z DEBUG true 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG ipa winsync plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG ipa-winsync-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG ipa_winsync_plugin_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libipa_winsync 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG FreeIPA project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG FreeIPA/1.0 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG only: set nsslapd-pluginPrecedence to '60', current value [] 2022-12-17T23:55:39Z DEBUG only: updated value ['60'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG ipa-winsync 2022-12-17T23:55:39Z DEBUG ipawinsyncacctdisable: 2022-12-17T23:55:39Z DEBUG both 2022-12-17T23:55:39Z DEBUG ipawinsyncdefaultgroupattr: 2022-12-17T23:55:39Z DEBUG ipaDefaultPrimaryGroup 2022-12-17T23:55:39Z DEBUG ipawinsyncdefaultgroupfilter: 2022-12-17T23:55:39Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2022-12-17T23:55:39Z DEBUG ipawinsyncforcesync: 2022-12-17T23:55:39Z DEBUG true 2022-12-17T23:55:39Z DEBUG ipawinsynchomedirattr: 2022-12-17T23:55:39Z DEBUG ipaHomesRootDir 2022-12-17T23:55:39Z DEBUG ipawinsyncloginshellattr: 2022-12-17T23:55:39Z DEBUG ipaDefaultLoginShell 2022-12-17T23:55:39Z DEBUG ipawinsyncnewentryfilter: 2022-12-17T23:55:39Z DEBUG (cn=ipaConfig) 2022-12-17T23:55:39Z DEBUG ipawinsyncnewuserocattr: 2022-12-17T23:55:39Z DEBUG ipauserobjectclasses 2022-12-17T23:55:39Z DEBUG ipawinsyncrealmattr: 2022-12-17T23:55:39Z DEBUG cn 2022-12-17T23:55:39Z DEBUG ipawinsyncrealmfilter: 2022-12-17T23:55:39Z DEBUG (objectclass=krbRealmContainer) 2022-12-17T23:55:39Z DEBUG ipawinsyncuserattr: 2022-12-17T23:55:39Z DEBUG uidNumber -1 2022-12-17T23:55:39Z DEBUG gidNumber -1 2022-12-17T23:55:39Z DEBUG ipawinsyncuserflatten: 2022-12-17T23:55:39Z DEBUG true 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG ipa winsync plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG ipa-winsync-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG ipa_winsync_plugin_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libipa_winsync 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG FreeIPA project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG FreeIPA/1.0 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPrecedence: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG [(2, 'nsslapd-pluginPrecedence', ['60'])] 2022-12-17T23:55:39Z DEBUG Updated 1 2022-12-17T23:55:39Z DEBUG update_entry modlist [(2, 'nsslapd-pluginPrecedence', [b'60'])] 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapdConfig 2022-12-17T23:55:39Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:39Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-betype: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:39Z DEBUG cn=schema 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-plugin: 2022-12-17T23:55:39Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:39Z DEBUG 16384 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-port: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-localuser: 2022-12-17T23:55:39Z DEBUG dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordInHistory: 2022-12-17T23:55:39Z DEBUG 6 2022-12-17T23:55:39Z DEBUG passwordUnlock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordGraceLimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordMustChange: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordWarning: 2022-12-17T23:55:39Z DEBUG 86400 2022-12-17T23:55:39Z DEBUG nsslapd-readonly: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:39Z DEBUG 16 2022-12-17T23:55:39Z DEBUG passwordLockout: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-localhost: 2022-12-17T23:55:39Z DEBUG master.redacted_domain.com 2022-12-17T23:55:39Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:39Z DEBUG 10000 2022-12-17T23:55:39Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordMinLength: 2022-12-17T23:55:39Z DEBUG 8 2022-12-17T23:55:39Z DEBUG passwordMinDigits: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinAlphas: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinUppers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinLowers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinSpecials: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMin8bit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinCategories: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordPalindrome: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictCheck: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictPath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordUserAttributes: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordBadWords: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordMaxSequence: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:39Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:39Z DEBUG replication-only 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG passwordMaxFailure: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:39Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-security: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordMaxAge: 2022-12-17T23:55:39Z DEBUG 8640000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:39Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:39Z DEBUG passwordChange: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securePort: 2022-12-17T23:55:39Z DEBUG 636 2022-12-17T23:55:39Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:39Z DEBUG 64 2022-12-17T23:55:39Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordExp: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG day 2022-12-17T23:55:39Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-nagle: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:39Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:39Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:39Z DEBUG uidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:39Z DEBUG gidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:39Z DEBUG dc=example,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:39Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:39Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-counters: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG passwordMinAge: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:39Z DEBUG 209715200 2022-12-17T23:55:39Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:39Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:39Z DEBUG 524288 2022-12-17T23:55:39Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:39Z DEBUG 1024 2022-12-17T23:55:39Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:39Z DEBUG allowed 2022-12-17T23:55:39Z DEBUG nsslapd-config: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:39Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:39Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:39Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:39Z DEBUG /tmp 2022-12-17T23:55:39Z DEBUG nsslapd-certdir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:39Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:39Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rundir: 2022-12-17T23:55:39Z DEBUG /run/dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:39Z DEBUG 300000 2022-12-17T23:55:39Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-localssf: 2022-12-17T23:55:39Z DEBUG 71 2022-12-17T23:55:39Z DEBUG nsslapd-minssf: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:39Z DEBUG next 2022-12-17T23:55:39Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:39Z DEBUG warn 2022-12-17T23:55:39Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:39Z DEBUG 20971520 2022-12-17T23:55:39Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:39Z DEBUG nolog 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:39Z DEBUG 128 2022-12-17T23:55:39Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:39Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:39Z DEBUG dirsrv-log 2022-12-17T23:55:39Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:39Z DEBUG process-safe 2022-12-17T23:55:39Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:39Z DEBUG 30 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:39Z DEBUG 300 2022-12-17T23:55:39Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordStorageScheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG passwordAdminDN: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:39Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:39Z DEBUG only: set nsslapd-sasl-mapping-fallback to 'on', current value ['on'] 2022-12-17T23:55:39Z DEBUG only: updated value ['on'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapdConfig 2022-12-17T23:55:39Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:39Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-betype: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:39Z DEBUG cn=schema 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-plugin: 2022-12-17T23:55:39Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:39Z DEBUG 16384 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-port: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-localuser: 2022-12-17T23:55:39Z DEBUG dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordInHistory: 2022-12-17T23:55:39Z DEBUG 6 2022-12-17T23:55:39Z DEBUG passwordUnlock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordGraceLimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordMustChange: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordWarning: 2022-12-17T23:55:39Z DEBUG 86400 2022-12-17T23:55:39Z DEBUG nsslapd-readonly: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:39Z DEBUG 16 2022-12-17T23:55:39Z DEBUG passwordLockout: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-localhost: 2022-12-17T23:55:39Z DEBUG master.redacted_domain.com 2022-12-17T23:55:39Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:39Z DEBUG 10000 2022-12-17T23:55:39Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordMinLength: 2022-12-17T23:55:39Z DEBUG 8 2022-12-17T23:55:39Z DEBUG passwordMinDigits: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinAlphas: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinUppers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinLowers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinSpecials: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMin8bit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinCategories: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordPalindrome: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictCheck: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictPath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordUserAttributes: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordBadWords: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordMaxSequence: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:39Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:39Z DEBUG replication-only 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG passwordMaxFailure: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:39Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-security: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordMaxAge: 2022-12-17T23:55:39Z DEBUG 8640000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:39Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:39Z DEBUG passwordChange: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securePort: 2022-12-17T23:55:39Z DEBUG 636 2022-12-17T23:55:39Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:39Z DEBUG 64 2022-12-17T23:55:39Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordExp: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG day 2022-12-17T23:55:39Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-nagle: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:39Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:39Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:39Z DEBUG uidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:39Z DEBUG gidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:39Z DEBUG dc=example,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:39Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:39Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-counters: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG passwordMinAge: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:39Z DEBUG 209715200 2022-12-17T23:55:39Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:39Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:39Z DEBUG 524288 2022-12-17T23:55:39Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:39Z DEBUG 1024 2022-12-17T23:55:39Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:39Z DEBUG allowed 2022-12-17T23:55:39Z DEBUG nsslapd-config: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:39Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:39Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:39Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:39Z DEBUG /tmp 2022-12-17T23:55:39Z DEBUG nsslapd-certdir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:39Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:39Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rundir: 2022-12-17T23:55:39Z DEBUG /run/dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:39Z DEBUG 300000 2022-12-17T23:55:39Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-localssf: 2022-12-17T23:55:39Z DEBUG 71 2022-12-17T23:55:39Z DEBUG nsslapd-minssf: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:39Z DEBUG next 2022-12-17T23:55:39Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:39Z DEBUG warn 2022-12-17T23:55:39Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:39Z DEBUG 20971520 2022-12-17T23:55:39Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:39Z DEBUG nolog 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:39Z DEBUG 128 2022-12-17T23:55:39Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:39Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:39Z DEBUG dirsrv-log 2022-12-17T23:55:39Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:39Z DEBUG process-safe 2022-12-17T23:55:39Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:39Z DEBUG 30 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:39Z DEBUG 300 2022-12-17T23:55:39Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordStorageScheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG passwordAdminDN: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:39Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG Full Principal 2022-12-17T23:55:39Z DEBUG nsSaslMapBaseDNTemplate: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsSaslMapFilterTemplate: 2022-12-17T23:55:39Z DEBUG (krbPrincipalName=\1@\2) 2022-12-17T23:55:39Z DEBUG nsSaslMapPriority: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsSaslMapRegexString: 2022-12-17T23:55:39Z DEBUG \(.*\)@\(.*\) 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSaslMapping 2022-12-17T23:55:39Z DEBUG addifnew: '10' to nsSaslMapPriority, current value ['10'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG Full Principal 2022-12-17T23:55:39Z DEBUG nsSaslMapBaseDNTemplate: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsSaslMapFilterTemplate: 2022-12-17T23:55:39Z DEBUG (krbPrincipalName=\1@\2) 2022-12-17T23:55:39Z DEBUG nsSaslMapPriority: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsSaslMapRegexString: 2022-12-17T23:55:39Z DEBUG \(.*\)@\(.*\) 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSaslMapping 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=Name Only,cn=mapping,cn=sasl,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=Name Only,cn=mapping,cn=sasl,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG Name Only 2022-12-17T23:55:39Z DEBUG nsSaslMapBaseDNTemplate: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsSaslMapFilterTemplate: 2022-12-17T23:55:39Z DEBUG (krbPrincipalName=&@REDACTED_DOMAIN.COM) 2022-12-17T23:55:39Z DEBUG nsSaslMapPriority: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsSaslMapRegexString: 2022-12-17T23:55:39Z DEBUG ^[^:@]+$ 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSaslMapping 2022-12-17T23:55:39Z DEBUG addifnew: '10' to nsSaslMapPriority, current value ['10'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=Name Only,cn=mapping,cn=sasl,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG Name Only 2022-12-17T23:55:39Z DEBUG nsSaslMapBaseDNTemplate: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsSaslMapFilterTemplate: 2022-12-17T23:55:39Z DEBUG (krbPrincipalName=&@REDACTED_DOMAIN.COM) 2022-12-17T23:55:39Z DEBUG nsSaslMapPriority: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsSaslMapRegexString: 2022-12-17T23:55:39Z DEBUG ^[^:@]+$ 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSaslMapping 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapdConfig 2022-12-17T23:55:39Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:39Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-betype: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:39Z DEBUG cn=schema 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-plugin: 2022-12-17T23:55:39Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:39Z DEBUG 16384 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-port: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-localuser: 2022-12-17T23:55:39Z DEBUG dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordInHistory: 2022-12-17T23:55:39Z DEBUG 6 2022-12-17T23:55:39Z DEBUG passwordUnlock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordGraceLimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordMustChange: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordWarning: 2022-12-17T23:55:39Z DEBUG 86400 2022-12-17T23:55:39Z DEBUG nsslapd-readonly: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:39Z DEBUG 16 2022-12-17T23:55:39Z DEBUG passwordLockout: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-localhost: 2022-12-17T23:55:39Z DEBUG master.redacted_domain.com 2022-12-17T23:55:39Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:39Z DEBUG 10000 2022-12-17T23:55:39Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordMinLength: 2022-12-17T23:55:39Z DEBUG 8 2022-12-17T23:55:39Z DEBUG passwordMinDigits: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinAlphas: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinUppers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinLowers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinSpecials: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMin8bit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinCategories: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordPalindrome: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictCheck: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictPath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordUserAttributes: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordBadWords: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordMaxSequence: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:39Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:39Z DEBUG replication-only 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG passwordMaxFailure: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:39Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-security: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordMaxAge: 2022-12-17T23:55:39Z DEBUG 8640000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:39Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:39Z DEBUG passwordChange: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securePort: 2022-12-17T23:55:39Z DEBUG 636 2022-12-17T23:55:39Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:39Z DEBUG 64 2022-12-17T23:55:39Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordExp: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG day 2022-12-17T23:55:39Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-nagle: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:39Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:39Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:39Z DEBUG uidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:39Z DEBUG gidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:39Z DEBUG dc=example,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:39Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:39Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-counters: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG passwordMinAge: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:39Z DEBUG 209715200 2022-12-17T23:55:39Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:39Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:39Z DEBUG 524288 2022-12-17T23:55:39Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:39Z DEBUG 1024 2022-12-17T23:55:39Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:39Z DEBUG allowed 2022-12-17T23:55:39Z DEBUG nsslapd-config: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:39Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:39Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:39Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:39Z DEBUG /tmp 2022-12-17T23:55:39Z DEBUG nsslapd-certdir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:39Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:39Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rundir: 2022-12-17T23:55:39Z DEBUG /run/dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:39Z DEBUG 300000 2022-12-17T23:55:39Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-localssf: 2022-12-17T23:55:39Z DEBUG 71 2022-12-17T23:55:39Z DEBUG nsslapd-minssf: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:39Z DEBUG next 2022-12-17T23:55:39Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:39Z DEBUG warn 2022-12-17T23:55:39Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:39Z DEBUG 20971520 2022-12-17T23:55:39Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:39Z DEBUG nolog 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:39Z DEBUG 128 2022-12-17T23:55:39Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:39Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:39Z DEBUG dirsrv-log 2022-12-17T23:55:39Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:39Z DEBUG process-safe 2022-12-17T23:55:39Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:39Z DEBUG 30 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:39Z DEBUG 300 2022-12-17T23:55:39Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordStorageScheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG passwordAdminDN: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:39Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:39Z DEBUG only: set nsslapd-allow-hashed-passwords to 'on', current value ['off'] 2022-12-17T23:55:39Z DEBUG only: updated value ['on'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapdConfig 2022-12-17T23:55:39Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:39Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-betype: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:39Z DEBUG cn=schema 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-plugin: 2022-12-17T23:55:39Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:39Z DEBUG 16384 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-port: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-localuser: 2022-12-17T23:55:39Z DEBUG dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordInHistory: 2022-12-17T23:55:39Z DEBUG 6 2022-12-17T23:55:39Z DEBUG passwordUnlock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordGraceLimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordMustChange: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordWarning: 2022-12-17T23:55:39Z DEBUG 86400 2022-12-17T23:55:39Z DEBUG nsslapd-readonly: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:39Z DEBUG 16 2022-12-17T23:55:39Z DEBUG passwordLockout: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-localhost: 2022-12-17T23:55:39Z DEBUG master.redacted_domain.com 2022-12-17T23:55:39Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:39Z DEBUG 10000 2022-12-17T23:55:39Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordMinLength: 2022-12-17T23:55:39Z DEBUG 8 2022-12-17T23:55:39Z DEBUG passwordMinDigits: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinAlphas: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinUppers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinLowers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinSpecials: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMin8bit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinCategories: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordPalindrome: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictCheck: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictPath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordUserAttributes: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordBadWords: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordMaxSequence: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:39Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:39Z DEBUG replication-only 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG passwordMaxFailure: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:39Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-security: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordMaxAge: 2022-12-17T23:55:39Z DEBUG 8640000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:39Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:39Z DEBUG passwordChange: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securePort: 2022-12-17T23:55:39Z DEBUG 636 2022-12-17T23:55:39Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:39Z DEBUG 64 2022-12-17T23:55:39Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordExp: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG day 2022-12-17T23:55:39Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-nagle: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:39Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:39Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:39Z DEBUG uidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:39Z DEBUG gidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:39Z DEBUG dc=example,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:39Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:39Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-counters: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG passwordMinAge: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:39Z DEBUG 209715200 2022-12-17T23:55:39Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:39Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:39Z DEBUG 524288 2022-12-17T23:55:39Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:39Z DEBUG 1024 2022-12-17T23:55:39Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:39Z DEBUG allowed 2022-12-17T23:55:39Z DEBUG nsslapd-config: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:39Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:39Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:39Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:39Z DEBUG /tmp 2022-12-17T23:55:39Z DEBUG nsslapd-certdir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:39Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:39Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rundir: 2022-12-17T23:55:39Z DEBUG /run/dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:39Z DEBUG 300000 2022-12-17T23:55:39Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-localssf: 2022-12-17T23:55:39Z DEBUG 71 2022-12-17T23:55:39Z DEBUG nsslapd-minssf: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:39Z DEBUG next 2022-12-17T23:55:39Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:39Z DEBUG warn 2022-12-17T23:55:39Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:39Z DEBUG 20971520 2022-12-17T23:55:39Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:39Z DEBUG nolog 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:39Z DEBUG 128 2022-12-17T23:55:39Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:39Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:39Z DEBUG dirsrv-log 2022-12-17T23:55:39Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:39Z DEBUG process-safe 2022-12-17T23:55:39Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:39Z DEBUG 30 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:39Z DEBUG 300 2022-12-17T23:55:39Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordStorageScheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG passwordAdminDN: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:39Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:39Z DEBUG [(2, 'nsslapd-allow-hashed-passwords', ['on'])] 2022-12-17T23:55:39Z DEBUG Updated 1 2022-12-17T23:55:39Z DEBUG update_entry modlist [(2, 'nsslapd-allow-hashed-passwords', [b'on'])] 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapdConfig 2022-12-17T23:55:39Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:39Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-betype: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:39Z DEBUG cn=schema 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-plugin: 2022-12-17T23:55:39Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:39Z DEBUG 16384 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-port: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-localuser: 2022-12-17T23:55:39Z DEBUG dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordInHistory: 2022-12-17T23:55:39Z DEBUG 6 2022-12-17T23:55:39Z DEBUG passwordUnlock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordGraceLimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordMustChange: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordWarning: 2022-12-17T23:55:39Z DEBUG 86400 2022-12-17T23:55:39Z DEBUG nsslapd-readonly: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:39Z DEBUG 16 2022-12-17T23:55:39Z DEBUG passwordLockout: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-localhost: 2022-12-17T23:55:39Z DEBUG master.redacted_domain.com 2022-12-17T23:55:39Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:39Z DEBUG 10000 2022-12-17T23:55:39Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordMinLength: 2022-12-17T23:55:39Z DEBUG 8 2022-12-17T23:55:39Z DEBUG passwordMinDigits: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinAlphas: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinUppers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinLowers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinSpecials: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMin8bit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinCategories: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordPalindrome: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictCheck: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictPath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordUserAttributes: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordBadWords: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordMaxSequence: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:39Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:39Z DEBUG replication-only 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG passwordMaxFailure: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:39Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-security: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordMaxAge: 2022-12-17T23:55:39Z DEBUG 8640000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:39Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:39Z DEBUG passwordChange: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securePort: 2022-12-17T23:55:39Z DEBUG 636 2022-12-17T23:55:39Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:39Z DEBUG 64 2022-12-17T23:55:39Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordExp: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG day 2022-12-17T23:55:39Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-nagle: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:39Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:39Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:39Z DEBUG uidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:39Z DEBUG gidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:39Z DEBUG dc=example,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:39Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:39Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-counters: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG passwordMinAge: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:39Z DEBUG 209715200 2022-12-17T23:55:39Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:39Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:39Z DEBUG 524288 2022-12-17T23:55:39Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:39Z DEBUG 1024 2022-12-17T23:55:39Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:39Z DEBUG allowed 2022-12-17T23:55:39Z DEBUG nsslapd-config: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:39Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:39Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:39Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:39Z DEBUG /tmp 2022-12-17T23:55:39Z DEBUG nsslapd-certdir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:39Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:39Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rundir: 2022-12-17T23:55:39Z DEBUG /run/dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:39Z DEBUG 300000 2022-12-17T23:55:39Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-localssf: 2022-12-17T23:55:39Z DEBUG 71 2022-12-17T23:55:39Z DEBUG nsslapd-minssf: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:39Z DEBUG next 2022-12-17T23:55:39Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:39Z DEBUG warn 2022-12-17T23:55:39Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:39Z DEBUG 20971520 2022-12-17T23:55:39Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:39Z DEBUG nolog 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:39Z DEBUG 128 2022-12-17T23:55:39Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:39Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:39Z DEBUG dirsrv-log 2022-12-17T23:55:39Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:39Z DEBUG process-safe 2022-12-17T23:55:39Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:39Z DEBUG 30 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:39Z DEBUG 300 2022-12-17T23:55:39Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordStorageScheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG passwordAdminDN: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:39Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:39Z DEBUG only: set nsslapd-ioblocktimeout to '10000', current value ['10000'] 2022-12-17T23:55:39Z DEBUG only: updated value ['10000'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapdConfig 2022-12-17T23:55:39Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:39Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-betype: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:39Z DEBUG cn=schema 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-plugin: 2022-12-17T23:55:39Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:39Z DEBUG 16384 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-port: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-localuser: 2022-12-17T23:55:39Z DEBUG dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordInHistory: 2022-12-17T23:55:39Z DEBUG 6 2022-12-17T23:55:39Z DEBUG passwordUnlock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordGraceLimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordMustChange: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordWarning: 2022-12-17T23:55:39Z DEBUG 86400 2022-12-17T23:55:39Z DEBUG nsslapd-readonly: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:39Z DEBUG 16 2022-12-17T23:55:39Z DEBUG passwordLockout: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-localhost: 2022-12-17T23:55:39Z DEBUG master.redacted_domain.com 2022-12-17T23:55:39Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:39Z DEBUG 10000 2022-12-17T23:55:39Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordMinLength: 2022-12-17T23:55:39Z DEBUG 8 2022-12-17T23:55:39Z DEBUG passwordMinDigits: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinAlphas: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinUppers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinLowers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinSpecials: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMin8bit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinCategories: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordPalindrome: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictCheck: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictPath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordUserAttributes: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordBadWords: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordMaxSequence: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:39Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:39Z DEBUG replication-only 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG passwordMaxFailure: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:39Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-security: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordMaxAge: 2022-12-17T23:55:39Z DEBUG 8640000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:39Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:39Z DEBUG passwordChange: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securePort: 2022-12-17T23:55:39Z DEBUG 636 2022-12-17T23:55:39Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:39Z DEBUG 64 2022-12-17T23:55:39Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordExp: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG day 2022-12-17T23:55:39Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-nagle: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:39Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:39Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:39Z DEBUG uidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:39Z DEBUG gidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:39Z DEBUG dc=example,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:39Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:39Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-counters: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG passwordMinAge: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:39Z DEBUG 209715200 2022-12-17T23:55:39Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:39Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:39Z DEBUG 524288 2022-12-17T23:55:39Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:39Z DEBUG 1024 2022-12-17T23:55:39Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:39Z DEBUG allowed 2022-12-17T23:55:39Z DEBUG nsslapd-config: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:39Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:39Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:39Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:39Z DEBUG /tmp 2022-12-17T23:55:39Z DEBUG nsslapd-certdir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:39Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:39Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rundir: 2022-12-17T23:55:39Z DEBUG /run/dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:39Z DEBUG 300000 2022-12-17T23:55:39Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-localssf: 2022-12-17T23:55:39Z DEBUG 71 2022-12-17T23:55:39Z DEBUG nsslapd-minssf: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:39Z DEBUG next 2022-12-17T23:55:39Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:39Z DEBUG warn 2022-12-17T23:55:39Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:39Z DEBUG 20971520 2022-12-17T23:55:39Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:39Z DEBUG nolog 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:39Z DEBUG 128 2022-12-17T23:55:39Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:39Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:39Z DEBUG dirsrv-log 2022-12-17T23:55:39Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:39Z DEBUG process-safe 2022-12-17T23:55:39Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:39Z DEBUG 30 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:39Z DEBUG 300 2022-12-17T23:55:39Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordStorageScheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG passwordAdminDN: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:39Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapdConfig 2022-12-17T23:55:39Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:39Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-betype: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:39Z DEBUG cn=schema 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-plugin: 2022-12-17T23:55:39Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:39Z DEBUG 16384 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-port: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-localuser: 2022-12-17T23:55:39Z DEBUG dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordInHistory: 2022-12-17T23:55:39Z DEBUG 6 2022-12-17T23:55:39Z DEBUG passwordUnlock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordGraceLimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordMustChange: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordWarning: 2022-12-17T23:55:39Z DEBUG 86400 2022-12-17T23:55:39Z DEBUG nsslapd-readonly: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:39Z DEBUG 16 2022-12-17T23:55:39Z DEBUG passwordLockout: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-localhost: 2022-12-17T23:55:39Z DEBUG master.redacted_domain.com 2022-12-17T23:55:39Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:39Z DEBUG 10000 2022-12-17T23:55:39Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordMinLength: 2022-12-17T23:55:39Z DEBUG 8 2022-12-17T23:55:39Z DEBUG passwordMinDigits: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinAlphas: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinUppers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinLowers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinSpecials: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMin8bit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinCategories: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordPalindrome: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictCheck: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictPath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordUserAttributes: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordBadWords: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordMaxSequence: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:39Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:39Z DEBUG replication-only 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG passwordMaxFailure: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:39Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-security: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordMaxAge: 2022-12-17T23:55:39Z DEBUG 8640000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:39Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:39Z DEBUG passwordChange: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securePort: 2022-12-17T23:55:39Z DEBUG 636 2022-12-17T23:55:39Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:39Z DEBUG 64 2022-12-17T23:55:39Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordExp: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG day 2022-12-17T23:55:39Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-nagle: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:39Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:39Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:39Z DEBUG uidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:39Z DEBUG gidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:39Z DEBUG dc=example,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:39Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:39Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-counters: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG passwordMinAge: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:39Z DEBUG 209715200 2022-12-17T23:55:39Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:39Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:39Z DEBUG 524288 2022-12-17T23:55:39Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:39Z DEBUG 1024 2022-12-17T23:55:39Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:39Z DEBUG allowed 2022-12-17T23:55:39Z DEBUG nsslapd-config: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:39Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:39Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:39Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:39Z DEBUG /tmp 2022-12-17T23:55:39Z DEBUG nsslapd-certdir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:39Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:39Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rundir: 2022-12-17T23:55:39Z DEBUG /run/dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:39Z DEBUG 300000 2022-12-17T23:55:39Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-localssf: 2022-12-17T23:55:39Z DEBUG 71 2022-12-17T23:55:39Z DEBUG nsslapd-minssf: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:39Z DEBUG next 2022-12-17T23:55:39Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:39Z DEBUG warn 2022-12-17T23:55:39Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:39Z DEBUG 20971520 2022-12-17T23:55:39Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:39Z DEBUG nolog 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:39Z DEBUG 128 2022-12-17T23:55:39Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:39Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:39Z DEBUG dirsrv-log 2022-12-17T23:55:39Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:39Z DEBUG process-safe 2022-12-17T23:55:39Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:39Z DEBUG 30 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:39Z DEBUG 300 2022-12-17T23:55:39Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordStorageScheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG passwordAdminDN: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:39Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:39Z DEBUG only: set nsslapd-enable-upgrade-hash to 'off', current value ['on'] 2022-12-17T23:55:39Z DEBUG only: updated value ['off'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapdConfig 2022-12-17T23:55:39Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:39Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-betype: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:39Z DEBUG cn=schema 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-plugin: 2022-12-17T23:55:39Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:39Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:39Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:39Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:39Z DEBUG 16384 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-port: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-localuser: 2022-12-17T23:55:39Z DEBUG dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordInHistory: 2022-12-17T23:55:39Z DEBUG 6 2022-12-17T23:55:39Z DEBUG passwordUnlock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordGraceLimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG passwordMustChange: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordWarning: 2022-12-17T23:55:39Z DEBUG 86400 2022-12-17T23:55:39Z DEBUG nsslapd-readonly: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:39Z DEBUG 16 2022-12-17T23:55:39Z DEBUG passwordLockout: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-localhost: 2022-12-17T23:55:39Z DEBUG master.redacted_domain.com 2022-12-17T23:55:39Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:39Z DEBUG 10000 2022-12-17T23:55:39Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG passwordMinLength: 2022-12-17T23:55:39Z DEBUG 8 2022-12-17T23:55:39Z DEBUG passwordMinDigits: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinAlphas: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinUppers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinLowers: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinSpecials: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMin8bit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMinCategories: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG passwordPalindrome: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictCheck: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordDictPath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordUserAttributes: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordBadWords: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordMaxSequence: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:39Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:39Z DEBUG replication-only 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG passwordMaxFailure: 2022-12-17T23:55:39Z DEBUG 3 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:39Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-security: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordMaxAge: 2022-12-17T23:55:39Z DEBUG 8640000 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:39Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:39Z DEBUG passwordChange: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:39Z DEBUG 256 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securePort: 2022-12-17T23:55:39Z DEBUG 636 2022-12-17T23:55:39Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:39Z DEBUG 64 2022-12-17T23:55:39Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG passwordExp: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG day 2022-12-17T23:55:39Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-nagle: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:39Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:39Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:39Z DEBUG uidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:39Z DEBUG gidNumber 2022-12-17T23:55:39Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:39Z DEBUG dc=example,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:39Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:39Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-counters: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:39Z DEBUG cn=Directory Manager 2022-12-17T23:55:39Z DEBUG passwordMinAge: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:39Z DEBUG 209715200 2022-12-17T23:55:39Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:39Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:39Z DEBUG 524288 2022-12-17T23:55:39Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:39Z DEBUG 1024 2022-12-17T23:55:39Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:39Z DEBUG allowed 2022-12-17T23:55:39Z DEBUG nsslapd-config: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:39Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:39Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:39Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:39Z DEBUG /tmp 2022-12-17T23:55:39Z DEBUG nsslapd-certdir: 2022-12-17T23:55:39Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:39Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:39Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rundir: 2022-12-17T23:55:39Z DEBUG /run/dirsrv 2022-12-17T23:55:39Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:39Z DEBUG 300000 2022-12-17T23:55:39Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-localssf: 2022-12-17T23:55:39Z DEBUG 71 2022-12-17T23:55:39Z DEBUG nsslapd-minssf: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:39Z DEBUG next 2022-12-17T23:55:39Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:39Z DEBUG warn 2022-12-17T23:55:39Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:39Z DEBUG 20971520 2022-12-17T23:55:39Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:39Z DEBUG nolog 2022-12-17T23:55:39Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:39Z DEBUG 2097152 2022-12-17T23:55:39Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:39Z DEBUG 128 2022-12-17T23:55:39Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:39Z DEBUG -10 2022-12-17T23:55:39Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 2 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:39Z DEBUG 100 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:39Z DEBUG 10 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:39Z DEBUG month 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:39Z DEBUG 5 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:39Z DEBUG week 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:39Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:39Z DEBUG dirsrv-log 2022-12-17T23:55:39Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:39Z DEBUG process-safe 2022-12-17T23:55:39Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:39Z DEBUG 3600 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:39Z DEBUG 30 2022-12-17T23:55:39Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:39Z DEBUG 300 2022-12-17T23:55:39Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG passwordStorageScheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG passwordAdminDN: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:39Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:39Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:39Z DEBUG 2022-12-17T23:55:39Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:39Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:39Z DEBUG [(2, 'nsslapd-enable-upgrade-hash', ['off'])] 2022-12-17T23:55:39Z DEBUG Updated 1 2022-12-17T23:55:39Z DEBUG update_entry modlist [(2, 'nsslapd-enable-upgrade-hash', [b'off'])] 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-config.update 0.992 sec 2022-12-17T23:55:39Z DEBUG Parsing update file '/usr/share/ipa/updates/10-db-locks.update' 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=bdb,cn=config,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=bdb,cn=config,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG bdb 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG extensibleobject 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsslapd-dbcachesize: 2022-12-17T23:55:39Z DEBUG 415353856 2022-12-17T23:55:39Z DEBUG nsslapd-db-logdirectory: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/db 2022-12-17T23:55:39Z DEBUG nsslapd-db-durable-transaction: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-db-transaction-wait: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-db-checkpoint-interval: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-db-compactdb-interval: 2022-12-17T23:55:39Z DEBUG 2592000 2022-12-17T23:55:39Z DEBUG nsslapd-db-compactdb-time: 2022-12-17T23:55:39Z DEBUG 23:59 2022-12-17T23:55:39Z DEBUG nsslapd-db-transaction-batch-val: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-db-transaction-batch-min-wait: 2022-12-17T23:55:39Z DEBUG 50 2022-12-17T23:55:39Z DEBUG nsslapd-db-transaction-batch-max-wait: 2022-12-17T23:55:39Z DEBUG 50 2022-12-17T23:55:39Z DEBUG nsslapd-db-logbuf-size: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-db-locks: 2022-12-17T23:55:39Z DEBUG 50000 2022-12-17T23:55:39Z DEBUG nsslapd-db-private-import-mem: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-db-home-directory: 2022-12-17T23:55:39Z DEBUG /dev/shm/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-import-cache-autosize: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-cache-autosize: 2022-12-17T23:55:39Z DEBUG 25 2022-12-17T23:55:39Z DEBUG nsslapd-cache-autosize-split: 2022-12-17T23:55:39Z DEBUG 25 2022-12-17T23:55:39Z DEBUG nsslapd-import-cachesize: 2022-12-17T23:55:39Z DEBUG 16777216 2022-12-17T23:55:39Z DEBUG nsslapd-search-bypass-filter-test: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-serial-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-db-deadlock-policy: 2022-12-17T23:55:39Z DEBUG 9 2022-12-17T23:55:39Z DEBUG nsslapd-db-locks-monitoring-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-db-locks-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 90 2022-12-17T23:55:39Z DEBUG nsslapd-db-locks-monitoring-pause: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG replace: 10000 not found, skipping 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=bdb,cn=config,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG bdb 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG extensibleobject 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsslapd-dbcachesize: 2022-12-17T23:55:39Z DEBUG 415353856 2022-12-17T23:55:39Z DEBUG nsslapd-db-logdirectory: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/db 2022-12-17T23:55:39Z DEBUG nsslapd-db-durable-transaction: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-db-transaction-wait: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-db-checkpoint-interval: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG nsslapd-db-compactdb-interval: 2022-12-17T23:55:39Z DEBUG 2592000 2022-12-17T23:55:39Z DEBUG nsslapd-db-compactdb-time: 2022-12-17T23:55:39Z DEBUG 23:59 2022-12-17T23:55:39Z DEBUG nsslapd-db-transaction-batch-val: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-db-transaction-batch-min-wait: 2022-12-17T23:55:39Z DEBUG 50 2022-12-17T23:55:39Z DEBUG nsslapd-db-transaction-batch-max-wait: 2022-12-17T23:55:39Z DEBUG 50 2022-12-17T23:55:39Z DEBUG nsslapd-db-logbuf-size: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-db-locks: 2022-12-17T23:55:39Z DEBUG 50000 2022-12-17T23:55:39Z DEBUG nsslapd-db-private-import-mem: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-db-home-directory: 2022-12-17T23:55:39Z DEBUG /dev/shm/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:39Z DEBUG nsslapd-import-cache-autosize: 2022-12-17T23:55:39Z DEBUG -1 2022-12-17T23:55:39Z DEBUG nsslapd-cache-autosize: 2022-12-17T23:55:39Z DEBUG 25 2022-12-17T23:55:39Z DEBUG nsslapd-cache-autosize-split: 2022-12-17T23:55:39Z DEBUG 25 2022-12-17T23:55:39Z DEBUG nsslapd-import-cachesize: 2022-12-17T23:55:39Z DEBUG 16777216 2022-12-17T23:55:39Z DEBUG nsslapd-search-bypass-filter-test: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-serial-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-db-deadlock-policy: 2022-12-17T23:55:39Z DEBUG 9 2022-12-17T23:55:39Z DEBUG nsslapd-db-locks-monitoring-enabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-db-locks-monitoring-threshold: 2022-12-17T23:55:39Z DEBUG 90 2022-12-17T23:55:39Z DEBUG nsslapd-db-locks-monitoring-pause: 2022-12-17T23:55:39Z DEBUG 500 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=config,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapd-lookthroughlimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-idlistscanlimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-directory: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/db 2022-12-17T23:55:39Z DEBUG nsslapd-import-cachesize: 2022-12-17T23:55:39Z DEBUG 16777216 2022-12-17T23:55:39Z DEBUG nsslapd-idl-switch: 2022-12-17T23:55:39Z DEBUG new 2022-12-17T23:55:39Z DEBUG nsslapd-search-bypass-filter-test: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-search-use-vlv-index: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-exclude-from-export: 2022-12-17T23:55:39Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2022-12-17T23:55:39Z DEBUG nsslapd-serial-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-subtree-rename-switch: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pagedlookthroughlimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-pagedidlistscanlimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-rangelookthroughlimit: 2022-12-17T23:55:39Z DEBUG 5000 2022-12-17T23:55:39Z DEBUG nsslapd-backend-opt-level: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-backend-implement: 2022-12-17T23:55:39Z DEBUG bdb 2022-12-17T23:55:39Z DEBUG remove: '50000' from nsslapd-db-locks, current value [] 2022-12-17T23:55:39Z DEBUG remove: '50000' not in nsslapd-db-locks 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapd-lookthroughlimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-mode: 2022-12-17T23:55:39Z DEBUG 600 2022-12-17T23:55:39Z DEBUG nsslapd-idlistscanlimit: 2022-12-17T23:55:39Z DEBUG 100000 2022-12-17T23:55:39Z DEBUG nsslapd-directory: 2022-12-17T23:55:39Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/db 2022-12-17T23:55:39Z DEBUG nsslapd-import-cachesize: 2022-12-17T23:55:39Z DEBUG 16777216 2022-12-17T23:55:39Z DEBUG nsslapd-idl-switch: 2022-12-17T23:55:39Z DEBUG new 2022-12-17T23:55:39Z DEBUG nsslapd-search-bypass-filter-test: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-search-use-vlv-index: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-exclude-from-export: 2022-12-17T23:55:39Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2022-12-17T23:55:39Z DEBUG nsslapd-serial-lock: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-subtree-rename-switch: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pagedlookthroughlimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-pagedidlistscanlimit: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG nsslapd-rangelookthroughlimit: 2022-12-17T23:55:39Z DEBUG 5000 2022-12-17T23:55:39Z DEBUG nsslapd-backend-opt-level: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG nsslapd-backend-implement: 2022-12-17T23:55:39Z DEBUG bdb 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-db-locks.update 0.017 sec 2022-12-17T23:55:39Z DEBUG Parsing update file '/usr/share/ipa/updates/10-enable-betxn.update' 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG 7-bit check 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce 7-bit clean attribute values 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NS7bitAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NS7bitAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpreoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-pluginarg0: 2022-12-17T23:55:39Z DEBUG uid 2022-12-17T23:55:39Z DEBUG nsslapd-pluginarg1: 2022-12-17T23:55:39Z DEBUG mail 2022-12-17T23:55:39Z DEBUG nsslapd-pluginarg2: 2022-12-17T23:55:39Z DEBUG , 2022-12-17T23:55:39Z DEBUG nsslapd-pluginarg3: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2022-12-17T23:55:39Z DEBUG only: updated value ['betxnpreoperation'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG 7-bit check 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce 7-bit clean attribute values 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NS7bitAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NS7bitAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpreoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-pluginarg0: 2022-12-17T23:55:39Z DEBUG uid 2022-12-17T23:55:39Z DEBUG nsslapd-pluginarg1: 2022-12-17T23:55:39Z DEBUG mail 2022-12-17T23:55:39Z DEBUG nsslapd-pluginarg2: 2022-12-17T23:55:39Z DEBUG , 2022-12-17T23:55:39Z DEBUG nsslapd-pluginarg3: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=attribute uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=attribute uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG attribute uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpreoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG uniqueness-across-all-subtrees: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG uid 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2022-12-17T23:55:39Z DEBUG only: updated value ['betxnpreoperation'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=attribute uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG attribute uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpreoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG uniqueness-across-all-subtrees: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG uid 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG automemberprocessmodifyops: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG Auto Membership Plugin 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginConfigArea: 2022-12-17T23:55:39Z DEBUG cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Auto Membership plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG Auto Membership 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG automember_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libautomember-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpreoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2022-12-17T23:55:39Z DEBUG only: updated value ['betxnpreoperation'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG automemberprocessmodifyops: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG Auto Membership Plugin 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginConfigArea: 2022-12-17T23:55:39Z DEBUG cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Auto Membership plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG Auto Membership 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG automember_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libautomember-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpreoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=Linked Attributes,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG Linked Attributes 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Linked Attributes plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG Linked Attributes 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG linked_attrs_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG liblinkedattrs-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpreoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsContainer 2022-12-17T23:55:39Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2022-12-17T23:55:39Z DEBUG only: updated value ['betxnpreoperation'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG Linked Attributes 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Linked Attributes plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG Linked Attributes 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG linked_attrs_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG liblinkedattrs-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpreoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsContainer 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG Managed Entries 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginConfigArea: 2022-12-17T23:55:39Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Managed Entries plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG Managed Entries 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG mep_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libmanagedentries-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpreoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsContainer 2022-12-17T23:55:39Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2022-12-17T23:55:39Z DEBUG only: updated value ['betxnpreoperation'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG Managed Entries 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginConfigArea: 2022-12-17T23:55:39Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Managed Entries plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG Managed Entries 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG mep_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libmanagedentries-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpreoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsContainer 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG MemberOf Plugin 2022-12-17T23:55:39Z DEBUG memberofattr: 2022-12-17T23:55:39Z DEBUG memberOf 2022-12-17T23:55:39Z DEBUG memberofgroupattr: 2022-12-17T23:55:39Z DEBUG member 2022-12-17T23:55:39Z DEBUG memberUser 2022-12-17T23:55:39Z DEBUG memberHost 2022-12-17T23:55:39Z DEBUG ipaOwner 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG memberof plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG memberof 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG memberof_postop_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libmemberof-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpostoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value ['betxnpostoperation'] 2022-12-17T23:55:39Z DEBUG only: updated value ['betxnpostoperation'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG MemberOf Plugin 2022-12-17T23:55:39Z DEBUG memberofattr: 2022-12-17T23:55:39Z DEBUG memberOf 2022-12-17T23:55:39Z DEBUG memberofgroupattr: 2022-12-17T23:55:39Z DEBUG member 2022-12-17T23:55:39Z DEBUG memberUser 2022-12-17T23:55:39Z DEBUG memberHost 2022-12-17T23:55:39Z DEBUG ipaOwner 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG memberof plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG memberof 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG memberof_postop_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libmemberof-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpostoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=Multisupplier Replication Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=Multisupplier Replication Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG Multisupplier Replication Plugin 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG AES 2022-12-17T23:55:39Z DEBUG Class of Service 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Multi-supplier Replication Plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG replication-multisupplier 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG replication_multisupplier_plugin_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libreplication-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG object 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2022-12-17T23:55:39Z DEBUG only: updated value ['on'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=Multisupplier Replication Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG Multisupplier Replication Plugin 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:39Z DEBUG ldbm database 2022-12-17T23:55:39Z DEBUG AES 2022-12-17T23:55:39Z DEBUG Class of Service 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Multi-supplier Replication Plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG replication-multisupplier 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG replication_multisupplier_plugin_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libreplication-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG object 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=PAM Pass Through Auth,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=PAM Pass Through Auth,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG PAM Pass Through Auth 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG pam_passthruauth_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libpam-passthru-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpreoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-pluginloadglobal: 2022-12-17T23:55:39Z DEBUG true 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG pamConfig 2022-12-17T23:55:39Z DEBUG pamExcludeSuffix: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG pamFallback: 2022-12-17T23:55:39Z DEBUG FALSE 2022-12-17T23:55:39Z DEBUG pamIDAttr: 2022-12-17T23:55:39Z DEBUG notUsedWithRDNMethod 2022-12-17T23:55:39Z DEBUG pamIDMapMethod: 2022-12-17T23:55:39Z DEBUG RDN 2022-12-17T23:55:39Z DEBUG pamMissingSuffix: 2022-12-17T23:55:39Z DEBUG ALLOW 2022-12-17T23:55:39Z DEBUG pamSecure: 2022-12-17T23:55:39Z DEBUG TRUE 2022-12-17T23:55:39Z DEBUG pamService: 2022-12-17T23:55:39Z DEBUG ldapserver 2022-12-17T23:55:39Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2022-12-17T23:55:39Z DEBUG only: updated value ['betxnpreoperation'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=PAM Pass Through Auth,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG PAM Pass Through Auth 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG off 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG pam_passthruauth_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libpam-passthru-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpreoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG none 2022-12-17T23:55:39Z DEBUG nsslapd-pluginloadglobal: 2022-12-17T23:55:39Z DEBUG true 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG pamConfig 2022-12-17T23:55:39Z DEBUG pamExcludeSuffix: 2022-12-17T23:55:39Z DEBUG cn=config 2022-12-17T23:55:39Z DEBUG pamFallback: 2022-12-17T23:55:39Z DEBUG FALSE 2022-12-17T23:55:39Z DEBUG pamIDAttr: 2022-12-17T23:55:39Z DEBUG notUsedWithRDNMethod 2022-12-17T23:55:39Z DEBUG pamIDMapMethod: 2022-12-17T23:55:39Z DEBUG RDN 2022-12-17T23:55:39Z DEBUG pamMissingSuffix: 2022-12-17T23:55:39Z DEBUG ALLOW 2022-12-17T23:55:39Z DEBUG pamSecure: 2022-12-17T23:55:39Z DEBUG TRUE 2022-12-17T23:55:39Z DEBUG pamService: 2022-12-17T23:55:39Z DEBUG ldapserver 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG referential integrity postoperation 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG referential integrity plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG referint 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG referint_postop_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libreferint-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpostoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG referint-logfile: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/referint 2022-12-17T23:55:39Z DEBUG referint-membership-attr: 2022-12-17T23:55:39Z DEBUG member 2022-12-17T23:55:39Z DEBUG uniquemember 2022-12-17T23:55:39Z DEBUG owner 2022-12-17T23:55:39Z DEBUG seeAlso 2022-12-17T23:55:39Z DEBUG referint-update-delay: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value ['betxnpostoperation'] 2022-12-17T23:55:39Z DEBUG only: updated value ['betxnpostoperation'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG referential integrity postoperation 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG referential integrity plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG referint 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG referint_postop_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libreferint-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpostoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:39Z DEBUG 40 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG referint-logfile: 2022-12-17T23:55:39Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/referint 2022-12-17T23:55:39Z DEBUG referint-membership-attr: 2022-12-17T23:55:39Z DEBUG member 2022-12-17T23:55:39Z DEBUG uniquemember 2022-12-17T23:55:39Z DEBUG owner 2022-12-17T23:55:39Z DEBUG seeAlso 2022-12-17T23:55:39Z DEBUG referint-update-delay: 2022-12-17T23:55:39Z DEBUG 0 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=Roles Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG Roles Plugin 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:39Z DEBUG State Change Plugin 2022-12-17T23:55:39Z DEBUG Views 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG roles plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG roles 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG roles_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libroles-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG object 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2022-12-17T23:55:39Z DEBUG only: updated value ['on'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG Roles Plugin 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:39Z DEBUG State Change Plugin 2022-12-17T23:55:39Z DEBUG Views 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG roles plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG roles 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG roles_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libroles-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG object 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=State Change Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG State Change Plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG state change notification service plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG statechange 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG statechange_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libstatechange-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpostoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value ['betxnpostoperation'] 2022-12-17T23:55:39Z DEBUG only: updated value ['betxnpostoperation'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG State Change Plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG state change notification service plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG statechange 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG statechange_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libstatechange-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpostoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=USN,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=USN,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG USN 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG USN (Update Sequence Number) plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG USN 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG usn_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libusn-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG object 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2022-12-17T23:55:39Z DEBUG only: updated value ['on'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=USN,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG USN 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG USN (Update Sequence Number) plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG USN 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG usn_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libusn-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG object 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=IPA MODRDN,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG IPA MODRDN 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG IPA MODRDN plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG IPA MODRDN 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG ipamodrdn_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libipa_modrdn 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpostoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG Red Hat, Inc. 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 1.0 2022-12-17T23:55:39Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG only: set nsslapd-plugintype to 'betxnpostoperation', current value ['betxnpostoperation'] 2022-12-17T23:55:39Z DEBUG only: updated value ['betxnpostoperation'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG IPA MODRDN 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG IPA MODRDN plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG IPA MODRDN 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG ipamodrdn_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libipa_modrdn 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG betxnpostoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG Red Hat, Inc. 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 1.0 2022-12-17T23:55:39Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:39Z DEBUG 60 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=ipa_pwd_extop,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG ipa_pwd_extop 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG IPA Password Extended Operation plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG IPA Password Manager 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG ipapwd_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libipa_pwd_extop 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG extendedop 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG FreeIPA project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG FreeIPA/1.0 2022-12-17T23:55:39Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-realmtree: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2022-12-17T23:55:39Z DEBUG only: updated value ['on'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG ipa_pwd_extop 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG IPA Password Extended Operation plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG IPA Password Manager 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG ipapwd_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libipa_pwd_extop 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG extendedop 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG FreeIPA project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG FreeIPA/1.0 2022-12-17T23:55:39Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-realmtree: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG New entry: cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG onlyifexist: 'on' to nsslapd-pluginbetxn, current value [] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG New entry: cn=NIS Server,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=NIS Server,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG onlyifexist: 'on' to nsslapd-pluginbetxn, current value [] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=NIS Server,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-enable-betxn.update 0.082 sec 2022-12-17T23:55:39Z DEBUG Parsing update file '/usr/share/ipa/updates/10-ipapwd.update' 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=ipa_pwd_extop,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG ipa_pwd_extop 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG IPA Password Extended Operation plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG IPA Password Manager 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG ipapwd_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libipa_pwd_extop 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG extendedop 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG FreeIPA project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG FreeIPA/1.0 2022-12-17T23:55:39Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-realmtree: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG add: '49' to nsslapd-pluginprecedence, current value [] 2022-12-17T23:55:39Z DEBUG add: updated value ['49'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG ipa_pwd_extop 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG IPA Password Extended Operation plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG IPA Password Manager 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG ipapwd_init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libipa_pwd_extop 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG extendedop 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG FreeIPA project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG FreeIPA/1.0 2022-12-17T23:55:39Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-realmtree: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:39Z DEBUG 49 2022-12-17T23:55:39Z DEBUG [(2, 'nsslapd-pluginprecedence', ['49'])] 2022-12-17T23:55:39Z DEBUG Updated 1 2022-12-17T23:55:39Z DEBUG update_entry modlist [(2, 'nsslapd-pluginprecedence', [b'49'])] 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-ipapwd.update 0.016 sec 2022-12-17T23:55:39Z DEBUG Parsing update file '/usr/share/ipa/updates/10-rootdse.update' 2022-12-17T23:55:39Z DEBUG Updating existing entry: 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG dataversion: 2022-12-17T23:55:39Z DEBUG 020221217235537020221217235537 2022-12-17T23:55:39Z DEBUG netscapemdsuffix: 2022-12-17T23:55:39Z DEBUG cn=ldap://dc=master,dc=redacted_domain,dc=com:0 2022-12-17T23:55:39Z DEBUG lastusn: 2022-12-17T23:55:39Z DEBUG 451 2022-12-17T23:55:39Z DEBUG ipatopologypluginversion: 2022-12-17T23:55:39Z DEBUG 1.0 2022-12-17T23:55:39Z DEBUG ipatopologyismanaged: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG ipaDomainLevel: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "rootdse anon read access"; allow(read,search,compare) userdn="ldap:///anyone";) 2022-12-17T23:55:39Z DEBUG add: 'namingContexts' to nsslapd-return-default-opattr, current value [] 2022-12-17T23:55:39Z DEBUG add: updated value ['namingContexts'] 2022-12-17T23:55:39Z DEBUG add: 'supportedControl' to nsslapd-return-default-opattr, current value ['namingContexts'] 2022-12-17T23:55:39Z DEBUG add: updated value ['namingContexts', 'supportedControl'] 2022-12-17T23:55:39Z DEBUG add: 'supportedExtension' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl'] 2022-12-17T23:55:39Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension'] 2022-12-17T23:55:39Z DEBUG add: 'supportedLDAPVersion' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension'] 2022-12-17T23:55:39Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion'] 2022-12-17T23:55:39Z DEBUG add: 'supportedSASLMechanisms' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion'] 2022-12-17T23:55:39Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms'] 2022-12-17T23:55:39Z DEBUG add: 'vendorName' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms'] 2022-12-17T23:55:39Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName'] 2022-12-17T23:55:39Z DEBUG add: 'vendorVersion' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName'] 2022-12-17T23:55:39Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName', 'vendorVersion'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG defaultnamingcontext: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG dataversion: 2022-12-17T23:55:39Z DEBUG 020221217235537020221217235537 2022-12-17T23:55:39Z DEBUG netscapemdsuffix: 2022-12-17T23:55:39Z DEBUG cn=ldap://dc=master,dc=redacted_domain,dc=com:0 2022-12-17T23:55:39Z DEBUG lastusn: 2022-12-17T23:55:39Z DEBUG 451 2022-12-17T23:55:39Z DEBUG ipatopologypluginversion: 2022-12-17T23:55:39Z DEBUG 1.0 2022-12-17T23:55:39Z DEBUG ipatopologyismanaged: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG ipaDomainLevel: 2022-12-17T23:55:39Z DEBUG 1 2022-12-17T23:55:39Z DEBUG aci: 2022-12-17T23:55:39Z DEBUG (targetattr != "aci")(version 3.0; aci "rootdse anon read access"; allow(read,search,compare) userdn="ldap:///anyone";) 2022-12-17T23:55:39Z DEBUG nsslapd-return-default-opattr: 2022-12-17T23:55:39Z DEBUG namingContexts 2022-12-17T23:55:39Z DEBUG supportedControl 2022-12-17T23:55:39Z DEBUG supportedExtension 2022-12-17T23:55:39Z DEBUG supportedLDAPVersion 2022-12-17T23:55:39Z DEBUG supportedSASLMechanisms 2022-12-17T23:55:39Z DEBUG vendorName 2022-12-17T23:55:39Z DEBUG vendorVersion 2022-12-17T23:55:39Z DEBUG [(2, 'nsslapd-return-default-opattr', ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName', 'vendorVersion'])] 2022-12-17T23:55:39Z DEBUG Updated 1 2022-12-17T23:55:39Z DEBUG update_entry modlist [(2, 'nsslapd-return-default-opattr', [b'namingContexts', b'supportedControl', b'supportedExtension', b'supportedLDAPVersion', b'supportedSASLMechanisms', b'vendorName', b'vendorVersion'])] 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-rootdse.update 0.016 sec 2022-12-17T23:55:39Z DEBUG Parsing update file '/usr/share/ipa/updates/10-selinuxusermap.update' 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=selinux,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=selinux,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsContainer 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG selinux 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=selinux,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsContainer 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG selinux 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=usermap,cn=selinux,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=usermap,cn=selinux,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsContainer 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG usermap 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=usermap,cn=selinux,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsContainer 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG usermap 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-selinuxusermap.update 0.005 sec 2022-12-17T23:55:39Z DEBUG Parsing update file '/usr/share/ipa/updates/10-uniqueness.update' 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=sudorule name uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=sudorule name uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG sudorule name uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG cn 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG cn=sudorules,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=sudorule name uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG sudorule name uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG cn 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG cn=sudorules,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG New entry: cn=certificate store subject uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=certificate store subject uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG certificate store subject uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG ipaCertSubject 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 1.1.0 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG Fedora Project 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=certificate store subject uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG certificate store subject uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG ipaCertSubject 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 1.1.0 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG Fedora Project 2022-12-17T23:55:39Z DEBUG New entry: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG certificate store issuer/serial uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG ipaCertIssuerSerial 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 1.1.0 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG Fedora Project 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG certificate store issuer/serial uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG ipaCertIssuerSerial 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 1.1.0 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG Fedora Project 2022-12-17T23:55:39Z DEBUG New entry: cn=uid uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG uid uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG uid 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG uniqueness-exclude-subtrees: 2022-12-17T23:55:39Z DEBUG cn=compat,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG uniqueness-across-all-subtrees: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-subtree-entries-oc: 2022-12-17T23:55:39Z DEBUG posixAccount 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 1.1.0 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG Fedora Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG uid uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG uid 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG uniqueness-exclude-subtrees: 2022-12-17T23:55:39Z DEBUG cn=compat,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG uniqueness-across-all-subtrees: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-subtree-entries-oc: 2022-12-17T23:55:39Z DEBUG posixAccount 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 1.1.0 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG Fedora Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=uid uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG uid uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG uid 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG uniqueness-exclude-subtrees: 2022-12-17T23:55:39Z DEBUG cn=compat,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG uniqueness-across-all-subtrees: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-subtree-entries-oc: 2022-12-17T23:55:39Z DEBUG posixAccount 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 1.1.0 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG Fedora Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG add: 'cn=compat,dc=redacted_domain,dc=com' to uniqueness-exclude-subtrees, current value ['cn=compat,dc=redacted_domain,dc=com', 'cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com'] 2022-12-17T23:55:39Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com', 'cn=compat,dc=redacted_domain,dc=com'] 2022-12-17T23:55:39Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com', 'cn=compat,dc=redacted_domain,dc=com'] 2022-12-17T23:55:39Z DEBUG add: updated value ['cn=compat,dc=redacted_domain,dc=com', 'cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com'] 2022-12-17T23:55:39Z DEBUG remove: 'off' from uniqueness-across-all-subtrees, current value ['on'] 2022-12-17T23:55:39Z DEBUG remove: 'off' not in uniqueness-across-all-subtrees 2022-12-17T23:55:39Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2022-12-17T23:55:39Z DEBUG add: updated value ['on'] 2022-12-17T23:55:39Z DEBUG add: 'posixAccount' to uniqueness-subtree-entries-oc, current value ['posixAccount'] 2022-12-17T23:55:39Z DEBUG add: updated value ['posixAccount'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG uid uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG uid 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG uniqueness-exclude-subtrees: 2022-12-17T23:55:39Z DEBUG cn=compat,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG uniqueness-across-all-subtrees: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-subtree-entries-oc: 2022-12-17T23:55:39Z DEBUG posixAccount 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 1.1.0 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG Fedora Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG krbPrincipalName uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG uniqueness-across-all-subtrees: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG krbPrincipalName 2022-12-17T23:55:39Z DEBUG uniqueness-exclude-subtrees: 2022-12-17T23:55:39Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com'] 2022-12-17T23:55:39Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com'] 2022-12-17T23:55:39Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2022-12-17T23:55:39Z DEBUG add: updated value ['on'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG krbPrincipalName uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG uniqueness-across-all-subtrees: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG krbPrincipalName 2022-12-17T23:55:39Z DEBUG uniqueness-exclude-subtrees: 2022-12-17T23:55:39Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG krbCanonicalName uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG uniqueness-across-all-subtrees: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG krbCanonicalName 2022-12-17T23:55:39Z DEBUG uniqueness-exclude-subtrees: 2022-12-17T23:55:39Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com'] 2022-12-17T23:55:39Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com'] 2022-12-17T23:55:39Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2022-12-17T23:55:39Z DEBUG add: updated value ['on'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG krbCanonicalName uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG uniqueness-across-all-subtrees: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG krbCanonicalName 2022-12-17T23:55:39Z DEBUG uniqueness-exclude-subtrees: 2022-12-17T23:55:39Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG Updating existing entry: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG ipaUniqueID uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG uniqueness-across-all-subtrees: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG ipaUniqueID 2022-12-17T23:55:39Z DEBUG uniqueness-exclude-subtrees: 2022-12-17T23:55:39Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com'] 2022-12-17T23:55:39Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com'] 2022-12-17T23:55:39Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2022-12-17T23:55:39Z DEBUG add: updated value ['on'] 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Final value after applying updates 2022-12-17T23:55:39Z DEBUG dn: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG ipaUniqueID uniqueness 2022-12-17T23:55:39Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:39Z DEBUG database 2022-12-17T23:55:39Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:39Z DEBUG Enforce unique attribute values 2022-12-17T23:55:39Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr 2022-12-17T23:55:39Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:39Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:39Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:39Z DEBUG libattr-unique-plugin 2022-12-17T23:55:39Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:39Z DEBUG preoperation 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:39Z DEBUG 389 Project 2022-12-17T23:55:39Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:39Z DEBUG 2.2.4 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG uniqueness-across-all-subtrees: 2022-12-17T23:55:39Z DEBUG on 2022-12-17T23:55:39Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:39Z DEBUG ipaUniqueID 2022-12-17T23:55:39Z DEBUG uniqueness-exclude-subtrees: 2022-12-17T23:55:39Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:39Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:39Z DEBUG [] 2022-12-17T23:55:39Z DEBUG Updated 0 2022-12-17T23:55:39Z DEBUG Done 2022-12-17T23:55:39Z DEBUG New entry: cn=caacl name uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG --------------------------------------------- 2022-12-17T23:55:39Z DEBUG Initial value 2022-12-17T23:55:39Z DEBUG dn: cn=caacl name uniqueness,cn=plugins,cn=config 2022-12-17T23:55:39Z DEBUG objectClass: 2022-12-17T23:55:39Z DEBUG top 2022-12-17T23:55:39Z DEBUG nsSlapdPlugin 2022-12-17T23:55:39Z DEBUG extensibleObject 2022-12-17T23:55:39Z DEBUG cn: 2022-12-17T23:55:39Z DEBUG caacl name uniqueness 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Enforce unique attribute values 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libattr-unique-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG preoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:40Z DEBUG cn 2022-12-17T23:55:40Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:40Z DEBUG cn=caacls,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG NSUniqueAttr 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 1.1.0 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG Fedora Project 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=caacl name uniqueness,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG caacl name uniqueness 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Enforce unique attribute values 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libattr-unique-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG preoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:40Z DEBUG cn 2022-12-17T23:55:40Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:40Z DEBUG cn=caacls,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG NSUniqueAttr 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 1.1.0 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG Fedora Project 2022-12-17T23:55:40Z DEBUG New entry: cn=ipaSubordinateIdEntry ipaOwner uniqueness,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaSubordinateIdEntry ipaOwner uniqueness,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaSubordinateIdEntry ipaOwner uniqueness 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Enforce unique attribute values of ipaOwner 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libattr-unique-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG preoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:40Z DEBUG ipaOwner 2022-12-17T23:55:40Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:40Z DEBUG cn=subids,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG uniqueness-across-all-subtrees: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG uniqueness-subtree-entries-oc: 2022-12-17T23:55:40Z DEBUG ipaSubordinateIdEntry 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG NSUniqueAttr 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 1.1.0 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG Fedora Project 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaSubordinateIdEntry ipaOwner uniqueness,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaSubordinateIdEntry ipaOwner uniqueness 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Enforce unique attribute values of ipaOwner 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libattr-unique-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG NSUniqueAttr_Init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG preoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG uniqueness-attribute-name: 2022-12-17T23:55:40Z DEBUG ipaOwner 2022-12-17T23:55:40Z DEBUG uniqueness-subtrees: 2022-12-17T23:55:40Z DEBUG cn=subids,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG uniqueness-across-all-subtrees: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG uniqueness-subtree-entries-oc: 2022-12-17T23:55:40Z DEBUG ipaSubordinateIdEntry 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG NSUniqueAttr 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 1.1.0 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG Fedora Project 2022-12-17T23:55:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-uniqueness.update 0.097 sec 2022-12-17T23:55:40Z DEBUG Parsing update file '/usr/share/ipa/updates/19-managed-entries.update' 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Managed Entries 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginConfigArea: 2022-12-17T23:55:40Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Managed Entries plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG Managed Entries 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG mep_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libmanagedentries-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG betxnpreoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG only: set nsslapd-pluginConfigArea to 'cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com', current value ['cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:40Z DEBUG only: updated value ['cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Managed Entries 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginConfigArea: 2022-12-17T23:55:40Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Managed Entries plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG Managed Entries 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG mep_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libmanagedentries-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG betxnpreoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Managed Entries 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Managed Entries 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Templates 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Templates 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Definitions 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Definitions 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/19-managed-entries.update 0.012 sec 2022-12-17T23:55:40Z DEBUG Parsing update file '/usr/share/ipa/updates/20-aci.update' 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ng,cn=alt,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ng,cn=alt,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ng 2022-12-17T23:55:40Z DEBUG add: '(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)' to aci, current value [] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ng,cn=alt,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ng 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG [(2, 'aci', ['(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG accounts 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG accounts 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG add: '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG computers 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG add: '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)' to aci, current value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG computers 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG computers 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG add: '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)' to aci, current value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG computers 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG add: '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG add: '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG add: '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG add: '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=replicas,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG replicas 2022-12-17T23:55:40Z DEBUG remove: '(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read access to replica configuration"; deny(read, search, compare) userdn = "ldap:///anyone";)' from aci, current value [] 2022-12-17T23:55:40Z DEBUG remove: '(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read access to replica configuration"; deny(read, search, compare) userdn = "ldap:///anyone";)' not in aci 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG replicas 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG masters 2022-12-17T23:55:40Z DEBUG add: '(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value [] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG masters 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG [(2, 'aci', ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG masters 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG add: '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG masters 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG masters 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG add: '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG masters 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG sysaccounts 2022-12-17T23:55:40Z DEBUG add: '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value [] 2022-12-17T23:55:40Z DEBUG add: updated value ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG sysaccounts 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [(2, 'aci', ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(2, 'aci', [b'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG krbContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG kerberos 2022-12-17T23:55:40Z DEBUG add: '(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)' to aci, current value [] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG krbContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG kerberos 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG [(2, 'aci', ['(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG add: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG add: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', b'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', b'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', b'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', b'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=tasks,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=tasks,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG tasks 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:40Z DEBUG remove: 'aci: (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from add, current value [] 2022-12-17T23:55:40Z DEBUG remove: 'aci: (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in add 2022-12-17T23:55:40Z DEBUG add: '(targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "*")(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: '(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "*")(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "*")(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=tasks,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG tasks 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=mapping tree,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=mapping tree,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG mapping tree 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG add: '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG remove: updated value ['(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=mapping tree,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG mapping tree 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [(1, 'aci', ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)']), (0, 'aci', ['(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(1, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)']), (0, 'aci', [b'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=mapping tree,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=mapping tree,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG mapping tree 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG add: '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastinitstatusjson || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalastupdatestatusjson || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastinitstatusjson || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalastupdatestatusjson || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=mapping tree,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG mapping tree 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastinitstatusjson || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalastupdatestatusjson || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastinitstatusjson || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalastupdatestatusjson || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastinitstatusjson || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalastupdatestatusjson || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=dc\=redacted_domain\,dc\=com,cn=mapping tree,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=dc\=redacted_domain\,dc\=com,cn=mapping tree,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG dc\=redacted_domain\,dc\=com 2022-12-17T23:55:40Z DEBUG nsslapd-backend: 2022-12-17T23:55:40Z DEBUG userRoot 2022-12-17T23:55:40Z DEBUG nsslapd-state: 2022-12-17T23:55:40Z DEBUG backend 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsMappingTree 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value [] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value [] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value [] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=dc\=redacted_domain\,dc\=com,cn=mapping tree,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG dc\=redacted_domain\,dc\=com 2022-12-17T23:55:40Z DEBUG nsslapd-backend: 2022-12-17T23:55:40Z DEBUG userRoot 2022-12-17T23:55:40Z DEBUG nsslapd-state: 2022-12-17T23:55:40Z DEBUG backend 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsMappingTree 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=o\=ipaca,cn=mapping tree,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=o\=ipaca,cn=mapping tree,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG o=ipaca 2022-12-17T23:55:40Z DEBUG nsslapd-backend: 2022-12-17T23:55:40Z DEBUG ipaca 2022-12-17T23:55:40Z DEBUG nsslapd-state: 2022-12-17T23:55:40Z DEBUG Backend 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsMappingTree 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "*")(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "*")(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "*")(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=o\=ipaca,cn=mapping tree,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG o=ipaca 2022-12-17T23:55:40Z DEBUG nsslapd-backend: 2022-12-17T23:55:40Z DEBUG ipaca 2022-12-17T23:55:40Z DEBUG nsslapd-state: 2022-12-17T23:55:40Z DEBUG Backend 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsMappingTree 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:40Z DEBUG (targetattr = "*")(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG config 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsslapdConfig 2022-12-17T23:55:40Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:40Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-betype: 2022-12-17T23:55:40Z DEBUG ldbm database 2022-12-17T23:55:40Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:40Z DEBUG cn=schema 2022-12-17T23:55:40Z DEBUG cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-plugin: 2022-12-17T23:55:40Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 10 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:40Z DEBUG 16384 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-port: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-localuser: 2022-12-17T23:55:40Z DEBUG dirsrv 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG passwordInHistory: 2022-12-17T23:55:40Z DEBUG 6 2022-12-17T23:55:40Z DEBUG passwordUnlock: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordGraceLimit: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG passwordMustChange: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:40Z DEBUG 100000 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG passwordWarning: 2022-12-17T23:55:40Z DEBUG 86400 2022-12-17T23:55:40Z DEBUG nsslapd-readonly: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:40Z DEBUG 16 2022-12-17T23:55:40Z DEBUG passwordLockout: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-localhost: 2022-12-17T23:55:40Z DEBUG master.redacted_domain.com 2022-12-17T23:55:40Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:40Z DEBUG 10000 2022-12-17T23:55:40Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:40Z DEBUG 40 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG passwordMinLength: 2022-12-17T23:55:40Z DEBUG 8 2022-12-17T23:55:40Z DEBUG passwordMinDigits: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinAlphas: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinUppers: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinLowers: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinSpecials: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMin8bit: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinCategories: 2022-12-17T23:55:40Z DEBUG 3 2022-12-17T23:55:40Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:40Z DEBUG 3 2022-12-17T23:55:40Z DEBUG passwordPalindrome: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordDictCheck: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordDictPath: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordUserAttributes: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordBadWords: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordMaxSequence: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:40Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:40Z DEBUG replication-only 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 500 2022-12-17T23:55:40Z DEBUG passwordMaxFailure: 2022-12-17T23:55:40Z DEBUG 3 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:40Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-security: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordMaxAge: 2022-12-17T23:55:40Z DEBUG 8640000 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 2 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:40Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:40Z DEBUG passwordChange: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:40Z DEBUG 256 2022-12-17T23:55:40Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:40Z DEBUG 256 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG nsslapd-securePort: 2022-12-17T23:55:40Z DEBUG 636 2022-12-17T23:55:40Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:40Z DEBUG 64 2022-12-17T23:55:40Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordExp: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG day 2022-12-17T23:55:40Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-nagle: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:40Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:40Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:40Z DEBUG cn=Directory Manager 2022-12-17T23:55:40Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:40Z DEBUG uidNumber 2022-12-17T23:55:40Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:40Z DEBUG gidNumber 2022-12-17T23:55:40Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:40Z DEBUG dc=example,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:40Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:40Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-counters: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 2 2022-12-17T23:55:40Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:40Z DEBUG cn=Directory Manager 2022-12-17T23:55:40Z DEBUG passwordMinAge: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:40Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:40Z DEBUG 209715200 2022-12-17T23:55:40Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:40Z DEBUG 2097152 2022-12-17T23:55:40Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:40Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:40Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:40Z DEBUG 524288 2022-12-17T23:55:40Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:40Z DEBUG 1024 2022-12-17T23:55:40Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:40Z DEBUG allowed 2022-12-17T23:55:40Z DEBUG nsslapd-config: 2022-12-17T23:55:40Z DEBUG cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:40Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:40Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:40Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:40Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:40Z DEBUG /tmp 2022-12-17T23:55:40Z DEBUG nsslapd-certdir: 2022-12-17T23:55:40Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:40Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:40Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:40Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:40Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-rundir: 2022-12-17T23:55:40Z DEBUG /run/dirsrv 2022-12-17T23:55:40Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:40Z DEBUG 300000 2022-12-17T23:55:40Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-localssf: 2022-12-17T23:55:40Z DEBUG 71 2022-12-17T23:55:40Z DEBUG nsslapd-minssf: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:40Z DEBUG next 2022-12-17T23:55:40Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:40Z DEBUG warn 2022-12-17T23:55:40Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:40Z DEBUG 2097152 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:40Z DEBUG 60 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:40Z DEBUG 20971520 2022-12-17T23:55:40Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:40Z DEBUG nolog 2022-12-17T23:55:40Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:40Z DEBUG 2097152 2022-12-17T23:55:40Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:40Z DEBUG 128 2022-12-17T23:55:40Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:40Z DEBUG -10 2022-12-17T23:55:40Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:40Z DEBUG -10 2022-12-17T23:55:40Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:40Z DEBUG -10 2022-12-17T23:55:40Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 2 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 500 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 10 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:40Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:40Z DEBUG dirsrv-log 2022-12-17T23:55:40Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:40Z DEBUG none 2022-12-17T23:55:40Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:40Z DEBUG process-safe 2022-12-17T23:55:40Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:40Z DEBUG 30 2022-12-17T23:55:40Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:40Z DEBUG 300 2022-12-17T23:55:40Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordStorageScheme: 2022-12-17T23:55:40Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:40Z DEBUG passwordAdminDN: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:40Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:40Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:40Z DEBUG remove: '(targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:System: Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:System: Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG config 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsslapdConfig 2022-12-17T23:55:40Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:40Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-betype: 2022-12-17T23:55:40Z DEBUG ldbm database 2022-12-17T23:55:40Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:40Z DEBUG cn=schema 2022-12-17T23:55:40Z DEBUG cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-plugin: 2022-12-17T23:55:40Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 10 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:40Z DEBUG 16384 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-port: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-localuser: 2022-12-17T23:55:40Z DEBUG dirsrv 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG passwordInHistory: 2022-12-17T23:55:40Z DEBUG 6 2022-12-17T23:55:40Z DEBUG passwordUnlock: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordGraceLimit: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG passwordMustChange: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:40Z DEBUG 100000 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG passwordWarning: 2022-12-17T23:55:40Z DEBUG 86400 2022-12-17T23:55:40Z DEBUG nsslapd-readonly: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:40Z DEBUG 16 2022-12-17T23:55:40Z DEBUG passwordLockout: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-localhost: 2022-12-17T23:55:40Z DEBUG master.redacted_domain.com 2022-12-17T23:55:40Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:40Z DEBUG 10000 2022-12-17T23:55:40Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:40Z DEBUG 40 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG passwordMinLength: 2022-12-17T23:55:40Z DEBUG 8 2022-12-17T23:55:40Z DEBUG passwordMinDigits: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinAlphas: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinUppers: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinLowers: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinSpecials: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMin8bit: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinCategories: 2022-12-17T23:55:40Z DEBUG 3 2022-12-17T23:55:40Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:40Z DEBUG 3 2022-12-17T23:55:40Z DEBUG passwordPalindrome: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordDictCheck: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordDictPath: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordUserAttributes: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordBadWords: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordMaxSequence: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:40Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:40Z DEBUG replication-only 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 500 2022-12-17T23:55:40Z DEBUG passwordMaxFailure: 2022-12-17T23:55:40Z DEBUG 3 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:40Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-security: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordMaxAge: 2022-12-17T23:55:40Z DEBUG 8640000 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 2 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:40Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:40Z DEBUG passwordChange: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:40Z DEBUG 256 2022-12-17T23:55:40Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:40Z DEBUG 256 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG nsslapd-securePort: 2022-12-17T23:55:40Z DEBUG 636 2022-12-17T23:55:40Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:40Z DEBUG 64 2022-12-17T23:55:40Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordExp: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG day 2022-12-17T23:55:40Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-nagle: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:40Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:40Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:40Z DEBUG cn=Directory Manager 2022-12-17T23:55:40Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:40Z DEBUG uidNumber 2022-12-17T23:55:40Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:40Z DEBUG gidNumber 2022-12-17T23:55:40Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:40Z DEBUG dc=example,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:40Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:40Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-counters: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 2 2022-12-17T23:55:40Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:40Z DEBUG cn=Directory Manager 2022-12-17T23:55:40Z DEBUG passwordMinAge: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:40Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:40Z DEBUG 209715200 2022-12-17T23:55:40Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:40Z DEBUG 2097152 2022-12-17T23:55:40Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:40Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:40Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:40Z DEBUG 524288 2022-12-17T23:55:40Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:40Z DEBUG 1024 2022-12-17T23:55:40Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:40Z DEBUG allowed 2022-12-17T23:55:40Z DEBUG nsslapd-config: 2022-12-17T23:55:40Z DEBUG cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:40Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:40Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:40Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:40Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:40Z DEBUG /tmp 2022-12-17T23:55:40Z DEBUG nsslapd-certdir: 2022-12-17T23:55:40Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:40Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:40Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:40Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:40Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-rundir: 2022-12-17T23:55:40Z DEBUG /run/dirsrv 2022-12-17T23:55:40Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:40Z DEBUG 300000 2022-12-17T23:55:40Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-localssf: 2022-12-17T23:55:40Z DEBUG 71 2022-12-17T23:55:40Z DEBUG nsslapd-minssf: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:40Z DEBUG next 2022-12-17T23:55:40Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:40Z DEBUG warn 2022-12-17T23:55:40Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:40Z DEBUG 2097152 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:40Z DEBUG 60 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:40Z DEBUG 20971520 2022-12-17T23:55:40Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:40Z DEBUG nolog 2022-12-17T23:55:40Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:40Z DEBUG 2097152 2022-12-17T23:55:40Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:40Z DEBUG 128 2022-12-17T23:55:40Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:40Z DEBUG -10 2022-12-17T23:55:40Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:40Z DEBUG -10 2022-12-17T23:55:40Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:40Z DEBUG -10 2022-12-17T23:55:40Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 2 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 500 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 10 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:40Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:40Z DEBUG dirsrv-log 2022-12-17T23:55:40Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:40Z DEBUG none 2022-12-17T23:55:40Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:40Z DEBUG process-safe 2022-12-17T23:55:40Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:40Z DEBUG 30 2022-12-17T23:55:40Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:40Z DEBUG 300 2022-12-17T23:55:40Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordStorageScheme: 2022-12-17T23:55:40Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:40Z DEBUG passwordAdminDN: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:40Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:40Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,cn=roles,cn=accounts,dc=redacted_domain,dc=com")(version 3.0; acl "No anonymous access to roles"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,cn=roles,cn=accounts,dc=redacted_domain,dc=com")(version 3.0; acl "No anonymous access to roles"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "memberOf || memberHost || memberUser")(version 3.0; acl "No anonymous access to member information"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "memberOf || memberHost || memberUser")(version 3.0; acl "No anonymous access to member information"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,dc=redacted_domain,dc=com")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,dc=redacted_domain,dc=com")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG hbac 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG hbac 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG sudo 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG sudo 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG accounts 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)'] 2022-12-17T23:55:40Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2022-12-17T23:55:40Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)'] 2022-12-17T23:55:40Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)'] 2022-12-17T23:55:40Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)'] 2022-12-17T23:55:40Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG accounts 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG add: '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG groups 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2022-12-17T23:55:40Z DEBUG add: '(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";)' to aci, current value ['(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)', '(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG groups 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2022-12-17T23:55:40Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG hostgroups 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2022-12-17T23:55:40Z DEBUG add: '(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";)' to aci, current value ['(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)', '(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG hostgroups 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2022-12-17T23:55:40Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG services 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2022-12-17T23:55:40Z DEBUG remove: '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaKrbPrincipal)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2022-12-17T23:55:40Z DEBUG remove: '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaKrbPrincipal)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG add: '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG services 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', b'(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ranges,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ranges,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ranges 2022-12-17T23:55:40Z DEBUG add: '(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)' to aci, current value [] 2022-12-17T23:55:40Z DEBUG add: updated value ['(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ranges,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ranges 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [(2, 'aci', ['(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(2, 'aci', [b'(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG sysaccounts 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG add: '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG sysaccounts 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG etc 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG add: '(target = "ldap:///cn=replication,cn=etc,dc=redacted_domain,dc=com")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=replication,cn=etc,dc=redacted_domain,dc=com")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG etc 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=replication,cn=etc,dc=redacted_domain,dc=com")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=replication,cn=etc,dc=redacted_domain,dc=com")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=replication,cn=etc,dc=redacted_domain,dc=com")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipa 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipa 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', b'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipa 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipa 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', b'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', b'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: krbPrincipalName=WELLKNOWN/ANONYMOUS@REDACTED_DOMAIN.COM,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: krbPrincipalName=WELLKNOWN/ANONYMOUS@REDACTED_DOMAIN.COM,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG krbprincipal 2022-12-17T23:55:40Z DEBUG krbprincipalaux 2022-12-17T23:55:40Z DEBUG krbTicketPolicyAux 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG ipaAllowedOperations 2022-12-17T23:55:40Z DEBUG krbPrincipalName: 2022-12-17T23:55:40Z DEBUG WELLKNOWN/ANONYMOUS@REDACTED_DOMAIN.COM 2022-12-17T23:55:40Z DEBUG krbCanonicalName: 2022-12-17T23:55:40Z DEBUG WELLKNOWN/ANONYMOUS@REDACTED_DOMAIN.COM 2022-12-17T23:55:40Z DEBUG krbLastPwdChange: 2022-12-17T23:55:40Z DEBUG 20221217235116Z 2022-12-17T23:55:40Z DEBUG krbPrincipalKey: 2022-12-17T23:55:40Z DEBUG XXXXXXXX 2022-12-17T23:55:40Z DEBUG krbExtraData: 2022-12-17T23:55:40Z DEBUG AAL0VZ5jcm9vdC9hZG1pbkBNT05JVkFHUk9VUC5DT00A 2022-12-17T23:55:40Z DEBUG ipaAllowedToPerform;read_keys: 2022-12-17T23:55:40Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2022-12-17T23:55:40Z DEBUG addifexist: 'ipaAllowedOperations' to objectclass, current value ['krbprincipal', 'krbprincipalaux', 'krbTicketPolicyAux', 'top', 'ipaAllowedOperations'] 2022-12-17T23:55:40Z DEBUG addifexist: set objectclass to ['krbprincipal', 'krbprincipalaux', 'krbTicketPolicyAux', 'top', 'ipaAllowedOperations', 'ipaAllowedOperations'] 2022-12-17T23:55:40Z DEBUG addifexist: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2022-12-17T23:55:40Z DEBUG addifexist: set aci to ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2022-12-17T23:55:40Z DEBUG addifexist: 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com' to ipaAllowedToPerform;read_keys, current value ['cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:40Z DEBUG addifexist: set ipaAllowedToPerform;read_keys to ['cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: krbPrincipalName=WELLKNOWN/ANONYMOUS@REDACTED_DOMAIN.COM,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG krbprincipal 2022-12-17T23:55:40Z DEBUG krbprincipalaux 2022-12-17T23:55:40Z DEBUG krbTicketPolicyAux 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG ipaAllowedOperations 2022-12-17T23:55:40Z DEBUG ipaAllowedOperations 2022-12-17T23:55:40Z DEBUG krbPrincipalName: 2022-12-17T23:55:40Z DEBUG WELLKNOWN/ANONYMOUS@REDACTED_DOMAIN.COM 2022-12-17T23:55:40Z DEBUG krbCanonicalName: 2022-12-17T23:55:40Z DEBUG WELLKNOWN/ANONYMOUS@REDACTED_DOMAIN.COM 2022-12-17T23:55:40Z DEBUG krbLastPwdChange: 2022-12-17T23:55:40Z DEBUG 20221217235116Z 2022-12-17T23:55:40Z DEBUG krbPrincipalKey: 2022-12-17T23:55:40Z DEBUG XXXXXXXX 2022-12-17T23:55:40Z DEBUG krbExtraData: 2022-12-17T23:55:40Z DEBUG AAL0VZ5jcm9vdC9hZG1pbkBNT05JVkFHUk9VUC5DT00A 2022-12-17T23:55:40Z DEBUG ipaAllowedToPerform;read_keys: 2022-12-17T23:55:40Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Posix IDs 2022-12-17T23:55:40Z DEBUG dnaExcludeScope: 2022-12-17T23:55:40Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG dnaFilter: 2022-12-17T23:55:40Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2022-12-17T23:55:40Z DEBUG dnaMagicRegen: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG dnaMaxValue: 2022-12-17T23:55:40Z DEBUG 1382999999 2022-12-17T23:55:40Z DEBUG dnaNextValue: 2022-12-17T23:55:40Z DEBUG 1382800000 2022-12-17T23:55:40Z DEBUG dnaScope: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG dnaSharedCfgDN: 2022-12-17T23:55:40Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG dnaThreshold: 2022-12-17T23:55:40Z DEBUG 500 2022-12-17T23:55:40Z DEBUG dnaType: 2022-12-17T23:55:40Z DEBUG uidNumber 2022-12-17T23:55:40Z DEBUG gidNumber 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG add: '(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Posix IDs 2022-12-17T23:55:40Z DEBUG dnaExcludeScope: 2022-12-17T23:55:40Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG dnaFilter: 2022-12-17T23:55:40Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2022-12-17T23:55:40Z DEBUG dnaMagicRegen: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG dnaMaxValue: 2022-12-17T23:55:40Z DEBUG 1382999999 2022-12-17T23:55:40Z DEBUG dnaNextValue: 2022-12-17T23:55:40Z DEBUG 1382800000 2022-12-17T23:55:40Z DEBUG dnaScope: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG dnaSharedCfgDN: 2022-12-17T23:55:40Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG dnaThreshold: 2022-12-17T23:55:40Z DEBUG 500 2022-12-17T23:55:40Z DEBUG dnaType: 2022-12-17T23:55:40Z DEBUG uidNumber 2022-12-17T23:55:40Z DEBUG gidNumber 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG userRoot 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsBackendInstance 2022-12-17T23:55:40Z DEBUG nsslapd-suffix: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-cachesize: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG nsslapd-cachememsize: 2022-12-17T23:55:40Z DEBUG 738197504 2022-12-17T23:55:40Z DEBUG nsslapd-readonly: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-require-index: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-require-internalop-index: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-dncachememsize: 2022-12-17T23:55:40Z DEBUG 134217728 2022-12-17T23:55:40Z DEBUG nsslapd-directory: 2022-12-17T23:55:40Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/db/userRoot 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG remove: '(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:40Z DEBUG add: '(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG add: updated value ['(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG userRoot 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsBackendInstance 2022-12-17T23:55:40Z DEBUG nsslapd-suffix: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-cachesize: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG nsslapd-cachememsize: 2022-12-17T23:55:40Z DEBUG 738197504 2022-12-17T23:55:40Z DEBUG nsslapd-readonly: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-require-index: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-require-internalop-index: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-dncachememsize: 2022-12-17T23:55:40Z DEBUG 134217728 2022-12-17T23:55:40Z DEBUG nsslapd-directory: 2022-12-17T23:55:40Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/db/userRoot 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-aci.update 0.309 sec 2022-12-17T23:55:40Z DEBUG Parsing update file '/usr/share/ipa/updates/20-autobind.update' 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=auto_bind,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=auto_bind,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG auto_bind 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=auto_bind,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG auto_bind 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG config 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsslapdConfig 2022-12-17T23:55:40Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:40Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-betype: 2022-12-17T23:55:40Z DEBUG ldbm database 2022-12-17T23:55:40Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:40Z DEBUG cn=schema 2022-12-17T23:55:40Z DEBUG cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-plugin: 2022-12-17T23:55:40Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 10 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:40Z DEBUG 16384 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-port: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-localuser: 2022-12-17T23:55:40Z DEBUG dirsrv 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG passwordInHistory: 2022-12-17T23:55:40Z DEBUG 6 2022-12-17T23:55:40Z DEBUG passwordUnlock: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordGraceLimit: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG passwordMustChange: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:40Z DEBUG 100000 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG passwordWarning: 2022-12-17T23:55:40Z DEBUG 86400 2022-12-17T23:55:40Z DEBUG nsslapd-readonly: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:40Z DEBUG 16 2022-12-17T23:55:40Z DEBUG passwordLockout: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-localhost: 2022-12-17T23:55:40Z DEBUG master.redacted_domain.com 2022-12-17T23:55:40Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:40Z DEBUG 10000 2022-12-17T23:55:40Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:40Z DEBUG 40 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG passwordMinLength: 2022-12-17T23:55:40Z DEBUG 8 2022-12-17T23:55:40Z DEBUG passwordMinDigits: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinAlphas: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinUppers: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinLowers: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinSpecials: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMin8bit: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinCategories: 2022-12-17T23:55:40Z DEBUG 3 2022-12-17T23:55:40Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:40Z DEBUG 3 2022-12-17T23:55:40Z DEBUG passwordPalindrome: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordDictCheck: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordDictPath: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordUserAttributes: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordBadWords: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordMaxSequence: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:40Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:40Z DEBUG replication-only 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 500 2022-12-17T23:55:40Z DEBUG passwordMaxFailure: 2022-12-17T23:55:40Z DEBUG 3 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:40Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-security: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordMaxAge: 2022-12-17T23:55:40Z DEBUG 8640000 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 2 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:40Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:40Z DEBUG passwordChange: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:40Z DEBUG 256 2022-12-17T23:55:40Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:40Z DEBUG 256 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG nsslapd-securePort: 2022-12-17T23:55:40Z DEBUG 636 2022-12-17T23:55:40Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:40Z DEBUG 64 2022-12-17T23:55:40Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordExp: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG day 2022-12-17T23:55:40Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-nagle: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:40Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:40Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:40Z DEBUG cn=Directory Manager 2022-12-17T23:55:40Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:40Z DEBUG uidNumber 2022-12-17T23:55:40Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:40Z DEBUG gidNumber 2022-12-17T23:55:40Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:40Z DEBUG dc=example,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:40Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:40Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-counters: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 2 2022-12-17T23:55:40Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:40Z DEBUG cn=Directory Manager 2022-12-17T23:55:40Z DEBUG passwordMinAge: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:40Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:40Z DEBUG 209715200 2022-12-17T23:55:40Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:40Z DEBUG 2097152 2022-12-17T23:55:40Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:40Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:40Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:40Z DEBUG 524288 2022-12-17T23:55:40Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:40Z DEBUG 1024 2022-12-17T23:55:40Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:40Z DEBUG allowed 2022-12-17T23:55:40Z DEBUG nsslapd-config: 2022-12-17T23:55:40Z DEBUG cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:40Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:40Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:40Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:40Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:40Z DEBUG /tmp 2022-12-17T23:55:40Z DEBUG nsslapd-certdir: 2022-12-17T23:55:40Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:40Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:40Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:40Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:40Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-rundir: 2022-12-17T23:55:40Z DEBUG /run/dirsrv 2022-12-17T23:55:40Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:40Z DEBUG 300000 2022-12-17T23:55:40Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-localssf: 2022-12-17T23:55:40Z DEBUG 71 2022-12-17T23:55:40Z DEBUG nsslapd-minssf: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:40Z DEBUG next 2022-12-17T23:55:40Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:40Z DEBUG warn 2022-12-17T23:55:40Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:40Z DEBUG 2097152 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:40Z DEBUG 60 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:40Z DEBUG 20971520 2022-12-17T23:55:40Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:40Z DEBUG nolog 2022-12-17T23:55:40Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:40Z DEBUG 2097152 2022-12-17T23:55:40Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:40Z DEBUG 128 2022-12-17T23:55:40Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:40Z DEBUG -10 2022-12-17T23:55:40Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:40Z DEBUG -10 2022-12-17T23:55:40Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:40Z DEBUG -10 2022-12-17T23:55:40Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 2 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 500 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 10 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:40Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:40Z DEBUG dirsrv-log 2022-12-17T23:55:40Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:40Z DEBUG none 2022-12-17T23:55:40Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:40Z DEBUG process-safe 2022-12-17T23:55:40Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:40Z DEBUG 30 2022-12-17T23:55:40Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:40Z DEBUG 300 2022-12-17T23:55:40Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordStorageScheme: 2022-12-17T23:55:40Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:40Z DEBUG passwordAdminDN: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:40Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:40Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:40Z DEBUG only: set nsslapd-ldapimaptoentries to 'on', current value ['off'] 2022-12-17T23:55:40Z DEBUG only: updated value ['on'] 2022-12-17T23:55:40Z DEBUG only: set nsslapd-ldapientrysearchbase to 'cn=auto_bind,cn=config', current value ['dc=example,dc=com'] 2022-12-17T23:55:40Z DEBUG only: updated value ['cn=auto_bind,cn=config'] 2022-12-17T23:55:40Z DEBUG only: set nsslapd-ldapidnmappingbase to 'cn=auto_bind,cn=config', current value ['cn=auto_bind,cn=config'] 2022-12-17T23:55:40Z DEBUG only: updated value ['cn=auto_bind,cn=config'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG config 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsslapdConfig 2022-12-17T23:55:40Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:40Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-betype: 2022-12-17T23:55:40Z DEBUG ldbm database 2022-12-17T23:55:40Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:40Z DEBUG cn=schema 2022-12-17T23:55:40Z DEBUG cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-plugin: 2022-12-17T23:55:40Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:40Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:40Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:40Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 10 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:40Z DEBUG 16384 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-port: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-localuser: 2022-12-17T23:55:40Z DEBUG dirsrv 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG passwordInHistory: 2022-12-17T23:55:40Z DEBUG 6 2022-12-17T23:55:40Z DEBUG passwordUnlock: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordGraceLimit: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG passwordMustChange: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:40Z DEBUG 100000 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG passwordWarning: 2022-12-17T23:55:40Z DEBUG 86400 2022-12-17T23:55:40Z DEBUG nsslapd-readonly: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:40Z DEBUG 16 2022-12-17T23:55:40Z DEBUG passwordLockout: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-localhost: 2022-12-17T23:55:40Z DEBUG master.redacted_domain.com 2022-12-17T23:55:40Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:40Z DEBUG 10000 2022-12-17T23:55:40Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:40Z DEBUG 40 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG passwordMinLength: 2022-12-17T23:55:40Z DEBUG 8 2022-12-17T23:55:40Z DEBUG passwordMinDigits: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinAlphas: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinUppers: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinLowers: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinSpecials: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMin8bit: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMinCategories: 2022-12-17T23:55:40Z DEBUG 3 2022-12-17T23:55:40Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:40Z DEBUG 3 2022-12-17T23:55:40Z DEBUG passwordPalindrome: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordDictCheck: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordDictPath: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordUserAttributes: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordBadWords: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordMaxSequence: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:40Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:40Z DEBUG replication-only 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 500 2022-12-17T23:55:40Z DEBUG passwordMaxFailure: 2022-12-17T23:55:40Z DEBUG 3 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:40Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-security: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordMaxAge: 2022-12-17T23:55:40Z DEBUG 8640000 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 2 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:40Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:40Z DEBUG passwordChange: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:40Z DEBUG 256 2022-12-17T23:55:40Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:40Z DEBUG 256 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG nsslapd-securePort: 2022-12-17T23:55:40Z DEBUG 636 2022-12-17T23:55:40Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:40Z DEBUG 64 2022-12-17T23:55:40Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG passwordExp: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG day 2022-12-17T23:55:40Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-nagle: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:40Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:40Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:40Z DEBUG cn=Directory Manager 2022-12-17T23:55:40Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:40Z DEBUG uidNumber 2022-12-17T23:55:40Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:40Z DEBUG gidNumber 2022-12-17T23:55:40Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:40Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:40Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:40Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-counters: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 2 2022-12-17T23:55:40Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:40Z DEBUG cn=Directory Manager 2022-12-17T23:55:40Z DEBUG passwordMinAge: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:40Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:40Z DEBUG 209715200 2022-12-17T23:55:40Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:40Z DEBUG 2097152 2022-12-17T23:55:40Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:40Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:40Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:40Z DEBUG 524288 2022-12-17T23:55:40Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:40Z DEBUG 1024 2022-12-17T23:55:40Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:40Z DEBUG allowed 2022-12-17T23:55:40Z DEBUG nsslapd-config: 2022-12-17T23:55:40Z DEBUG cn=config 2022-12-17T23:55:40Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:40Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:40Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:40Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:40Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:40Z DEBUG /tmp 2022-12-17T23:55:40Z DEBUG nsslapd-certdir: 2022-12-17T23:55:40Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:40Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:40Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:40Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:40Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:40Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-rundir: 2022-12-17T23:55:40Z DEBUG /run/dirsrv 2022-12-17T23:55:40Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:40Z DEBUG 300000 2022-12-17T23:55:40Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-localssf: 2022-12-17T23:55:40Z DEBUG 71 2022-12-17T23:55:40Z DEBUG nsslapd-minssf: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:40Z DEBUG next 2022-12-17T23:55:40Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:40Z DEBUG warn 2022-12-17T23:55:40Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:40Z DEBUG 2097152 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:40Z DEBUG 60 2022-12-17T23:55:40Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:40Z DEBUG 20971520 2022-12-17T23:55:40Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:40Z DEBUG nolog 2022-12-17T23:55:40Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:40Z DEBUG 2097152 2022-12-17T23:55:40Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:40Z DEBUG 128 2022-12-17T23:55:40Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:40Z DEBUG -10 2022-12-17T23:55:40Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:40Z DEBUG -10 2022-12-17T23:55:40Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:40Z DEBUG -10 2022-12-17T23:55:40Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:40Z DEBUG -1 2022-12-17T23:55:40Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 2 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:40Z DEBUG 600 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:40Z DEBUG 500 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:40Z DEBUG 100 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:40Z DEBUG 1 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:40Z DEBUG 10 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:40Z DEBUG month 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:40Z DEBUG week 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:40Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:40Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:40Z DEBUG dirsrv-log 2022-12-17T23:55:40Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:40Z DEBUG none 2022-12-17T23:55:40Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:40Z DEBUG process-safe 2022-12-17T23:55:40Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:40Z DEBUG 3600 2022-12-17T23:55:40Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:40Z DEBUG 30 2022-12-17T23:55:40Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:40Z DEBUG 300 2022-12-17T23:55:40Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG passwordStorageScheme: 2022-12-17T23:55:40Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:40Z DEBUG passwordAdminDN: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:40Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:40Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:40Z DEBUG off 2022-12-17T23:55:40Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:40Z DEBUG 2022-12-17T23:55:40Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:40Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:40Z DEBUG [(2, 'nsslapd-ldapientrysearchbase', ['cn=auto_bind,cn=config']), (2, 'nsslapd-ldapimaptoentries', ['on'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(2, 'nsslapd-ldapientrysearchbase', [b'cn=auto_bind,cn=config']), (2, 'nsslapd-ldapimaptoentries', [b'on'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Deleting entry cn=root-autobind,cn=config 2022-12-17T23:55:40Z DEBUG cn=root-autobind,cn=config did not exist:no such entry 2022-12-17T23:55:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-autobind.update 0.120 sec 2022-12-17T23:55:40Z DEBUG Parsing update file '/usr/share/ipa/updates/20-default_password_policy.update' 2022-12-17T23:55:40Z DEBUG New entry: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG krbPwdPolicy 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default Host Password Policy 2022-12-17T23:55:40Z DEBUG krbMinPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinDiffChars: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinLength: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdHistoryLength: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbMaxPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMaxFailure: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdFailureCountInterval: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdLockoutDuration: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG krbPwdPolicy 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default Host Password Policy 2022-12-17T23:55:40Z DEBUG krbMinPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinDiffChars: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinLength: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdHistoryLength: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbMaxPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMaxFailure: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdFailureCountInterval: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdLockoutDuration: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG New entry: cn=Default Service Password Policy,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Default Service Password Policy,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG krbPwdPolicy 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default Service Password Policy 2022-12-17T23:55:40Z DEBUG krbMinPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinDiffChars: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinLength: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdHistoryLength: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbMaxPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMaxFailure: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdFailureCountInterval: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdLockoutDuration: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Default Service Password Policy,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG krbPwdPolicy 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default Service Password Policy 2022-12-17T23:55:40Z DEBUG krbMinPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinDiffChars: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinLength: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdHistoryLength: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbMaxPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMaxFailure: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdFailureCountInterval: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdLockoutDuration: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG New entry: cn=Kerberos Service Password Policy,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Kerberos Service Password Policy,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Kerberos Service Password Policy 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Kerberos Service Password Policy,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Kerberos Service Password Policy 2022-12-17T23:55:40Z DEBUG New entry: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG krbPwdPolicy 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default Kerberos Service Password Policy 2022-12-17T23:55:40Z DEBUG krbMinPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinDiffChars: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinLength: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdHistoryLength: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbMaxPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMaxFailure: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdFailureCountInterval: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdLockoutDuration: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG krbPwdPolicy 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default Kerberos Service Password Policy 2022-12-17T23:55:40Z DEBUG krbMinPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinDiffChars: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinLength: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdHistoryLength: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbMaxPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMaxFailure: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdFailureCountInterval: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdLockoutDuration: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG New entry: cn=Default System Accounts Password Policy,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Default System Accounts Password Policy,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG krbPwdPolicy 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default System Accounts Password Policy 2022-12-17T23:55:40Z DEBUG krbMinPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinDiffChars: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinLength: 2022-12-17T23:55:40Z DEBUG 8 2022-12-17T23:55:40Z DEBUG krbPwdHistoryLength: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbMaxPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMaxFailure: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdFailureCountInterval: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdLockoutDuration: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Default System Accounts Password Policy,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG krbPwdPolicy 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default System Accounts Password Policy 2022-12-17T23:55:40Z DEBUG krbMinPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinDiffChars: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMinLength: 2022-12-17T23:55:40Z DEBUG 8 2022-12-17T23:55:40Z DEBUG krbPwdHistoryLength: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbMaxPwdLife: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdMaxFailure: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdFailureCountInterval: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG krbPwdLockoutDuration: 2022-12-17T23:55:40Z DEBUG 0 2022-12-17T23:55:40Z DEBUG New entry: cn=cosTemplates,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=cosTemplates,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG cosTemplates 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=cosTemplates,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG cosTemplates 2022-12-17T23:55:40Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cosTemplate 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG krbContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default Password Policy 2022-12-17T23:55:40Z DEBUG cosPriority: 2022-12-17T23:55:40Z DEBUG 10000000000 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference: 2022-12-17T23:55:40Z DEBUG cn=Default Host Password Policy,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cosTemplate 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG krbContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default Password Policy 2022-12-17T23:55:40Z DEBUG cosPriority: 2022-12-17T23:55:40Z DEBUG 10000000000 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference: 2022-12-17T23:55:40Z DEBUG cn=Default Host Password Policy,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG New entry: cn=Default Password Policy,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG description: 2022-12-17T23:55:40Z DEBUG Default Password Policy for Hosts 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG ldapsubentry 2022-12-17T23:55:40Z DEBUG cosSuperDefinition 2022-12-17T23:55:40Z DEBUG cosPointerDefinition 2022-12-17T23:55:40Z DEBUG cosTemplateDn: 2022-12-17T23:55:40Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG cosAttribute: 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference default 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG description: 2022-12-17T23:55:40Z DEBUG Default Password Policy for Hosts 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG ldapsubentry 2022-12-17T23:55:40Z DEBUG cosSuperDefinition 2022-12-17T23:55:40Z DEBUG cosPointerDefinition 2022-12-17T23:55:40Z DEBUG cosTemplateDn: 2022-12-17T23:55:40Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG cosAttribute: 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference default 2022-12-17T23:55:40Z DEBUG New entry: cn=cosTemplates,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=cosTemplates,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG cosTemplates 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=cosTemplates,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG cosTemplates 2022-12-17T23:55:40Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cosTemplate 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG krbContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default Password Policy 2022-12-17T23:55:40Z DEBUG cosPriority: 2022-12-17T23:55:40Z DEBUG 10000000000 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference: 2022-12-17T23:55:40Z DEBUG cn=Default Service Password Policy,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cosTemplate 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG krbContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default Password Policy 2022-12-17T23:55:40Z DEBUG cosPriority: 2022-12-17T23:55:40Z DEBUG 10000000000 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference: 2022-12-17T23:55:40Z DEBUG cn=Default Service Password Policy,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG New entry: cn=Default Password Policy,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG description: 2022-12-17T23:55:40Z DEBUG Default Password Policy for Services 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG ldapsubentry 2022-12-17T23:55:40Z DEBUG cosSuperDefinition 2022-12-17T23:55:40Z DEBUG cosPointerDefinition 2022-12-17T23:55:40Z DEBUG cosTemplateDn: 2022-12-17T23:55:40Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG cosAttribute: 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference default 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG description: 2022-12-17T23:55:40Z DEBUG Default Password Policy for Services 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG ldapsubentry 2022-12-17T23:55:40Z DEBUG cosSuperDefinition 2022-12-17T23:55:40Z DEBUG cosPointerDefinition 2022-12-17T23:55:40Z DEBUG cosTemplateDn: 2022-12-17T23:55:40Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG cosAttribute: 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference default 2022-12-17T23:55:40Z DEBUG New entry: cn=cosTemplates,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=cosTemplates,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG cosTemplates 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=cosTemplates,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG cosTemplates 2022-12-17T23:55:40Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cosTemplate 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG krbContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default Password Policy 2022-12-17T23:55:40Z DEBUG cosPriority: 2022-12-17T23:55:40Z DEBUG 10000000000 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference: 2022-12-17T23:55:40Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cosTemplate 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG krbContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default Password Policy 2022-12-17T23:55:40Z DEBUG cosPriority: 2022-12-17T23:55:40Z DEBUG 10000000000 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference: 2022-12-17T23:55:40Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG New entry: cn=Default Password Policy,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG description: 2022-12-17T23:55:40Z DEBUG Default Password Policy for Kerberos Services 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG ldapsubentry 2022-12-17T23:55:40Z DEBUG cosSuperDefinition 2022-12-17T23:55:40Z DEBUG cosPointerDefinition 2022-12-17T23:55:40Z DEBUG cosTemplateDn: 2022-12-17T23:55:40Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG cosAttribute: 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference default 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG description: 2022-12-17T23:55:40Z DEBUG Default Password Policy for Kerberos Services 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG ldapsubentry 2022-12-17T23:55:40Z DEBUG cosSuperDefinition 2022-12-17T23:55:40Z DEBUG cosPointerDefinition 2022-12-17T23:55:40Z DEBUG cosTemplateDn: 2022-12-17T23:55:40Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG cosAttribute: 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference default 2022-12-17T23:55:40Z DEBUG New entry: cn=cosTemplates,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=cosTemplates,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG cosTemplates 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=cosTemplates,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG cosTemplates 2022-12-17T23:55:40Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cosTemplate 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG krbContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default Password Policy 2022-12-17T23:55:40Z DEBUG cosPriority: 2022-12-17T23:55:40Z DEBUG 10000000000 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference: 2022-12-17T23:55:40Z DEBUG cn=Default System Accounts Password Policy,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cosTemplate 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG krbContainer 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Default Password Policy 2022-12-17T23:55:40Z DEBUG cosPriority: 2022-12-17T23:55:40Z DEBUG 10000000000 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference: 2022-12-17T23:55:40Z DEBUG cn=Default System Accounts Password Policy,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG New entry: cn=Default Password Policy,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG description: 2022-12-17T23:55:40Z DEBUG Default Password Policy for System Accounts 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG ldapsubentry 2022-12-17T23:55:40Z DEBUG cosSuperDefinition 2022-12-17T23:55:40Z DEBUG cosPointerDefinition 2022-12-17T23:55:40Z DEBUG cosTemplateDn: 2022-12-17T23:55:40Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG cosAttribute: 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference default 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Default Password Policy,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG description: 2022-12-17T23:55:40Z DEBUG Default Password Policy for System Accounts 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG ldapsubentry 2022-12-17T23:55:40Z DEBUG cosSuperDefinition 2022-12-17T23:55:40Z DEBUG cosPointerDefinition 2022-12-17T23:55:40Z DEBUG cosTemplateDn: 2022-12-17T23:55:40Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG cosAttribute: 2022-12-17T23:55:40Z DEBUG krbPwdPolicyReference default 2022-12-17T23:55:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-default_password_policy.update 0.096 sec 2022-12-17T23:55:40Z DEBUG Parsing update file '/usr/share/ipa/updates/20-dna.update' 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipa-winsync,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipa-winsync 2022-12-17T23:55:40Z DEBUG ipawinsyncacctdisable: 2022-12-17T23:55:40Z DEBUG both 2022-12-17T23:55:40Z DEBUG ipawinsyncdefaultgroupattr: 2022-12-17T23:55:40Z DEBUG ipaDefaultPrimaryGroup 2022-12-17T23:55:40Z DEBUG ipawinsyncdefaultgroupfilter: 2022-12-17T23:55:40Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2022-12-17T23:55:40Z DEBUG ipawinsyncforcesync: 2022-12-17T23:55:40Z DEBUG true 2022-12-17T23:55:40Z DEBUG ipawinsynchomedirattr: 2022-12-17T23:55:40Z DEBUG ipaHomesRootDir 2022-12-17T23:55:40Z DEBUG ipawinsyncloginshellattr: 2022-12-17T23:55:40Z DEBUG ipaDefaultLoginShell 2022-12-17T23:55:40Z DEBUG ipawinsyncnewentryfilter: 2022-12-17T23:55:40Z DEBUG (cn=ipaConfig) 2022-12-17T23:55:40Z DEBUG ipawinsyncnewuserocattr: 2022-12-17T23:55:40Z DEBUG ipauserobjectclasses 2022-12-17T23:55:40Z DEBUG ipawinsyncrealmattr: 2022-12-17T23:55:40Z DEBUG cn 2022-12-17T23:55:40Z DEBUG ipawinsyncrealmfilter: 2022-12-17T23:55:40Z DEBUG (objectclass=krbRealmContainer) 2022-12-17T23:55:40Z DEBUG ipawinsyncuserattr: 2022-12-17T23:55:40Z DEBUG uidNumber -1 2022-12-17T23:55:40Z DEBUG gidNumber -1 2022-12-17T23:55:40Z DEBUG ipawinsyncuserflatten: 2022-12-17T23:55:40Z DEBUG true 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG ipa winsync plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG ipa-winsync-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG ipa_winsync_plugin_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libipa_winsync 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG preoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG FreeIPA project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG FreeIPA/1.0 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:40Z DEBUG 60 2022-12-17T23:55:40Z DEBUG remove: 'uidNumber 999' from ipaWinSyncUserAttr, current value ['uidNumber -1', 'gidNumber -1'] 2022-12-17T23:55:40Z DEBUG remove: 'uidNumber 999' not in ipaWinSyncUserAttr 2022-12-17T23:55:40Z DEBUG remove: 'gidNumber 999' from ipaWinSyncUserAttr, current value ['uidNumber -1', 'gidNumber -1'] 2022-12-17T23:55:40Z DEBUG remove: 'gidNumber 999' not in ipaWinSyncUserAttr 2022-12-17T23:55:40Z DEBUG add: 'uidNumber -1' to ipaWinSyncUserAttr, current value ['uidNumber -1', 'gidNumber -1'] 2022-12-17T23:55:40Z DEBUG add: updated value ['gidNumber -1', 'uidNumber -1'] 2022-12-17T23:55:40Z DEBUG add: 'gidNumber -1' to ipaWinSyncUserAttr, current value ['gidNumber -1', 'uidNumber -1'] 2022-12-17T23:55:40Z DEBUG add: updated value ['uidNumber -1', 'gidNumber -1'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipa-winsync 2022-12-17T23:55:40Z DEBUG ipawinsyncacctdisable: 2022-12-17T23:55:40Z DEBUG both 2022-12-17T23:55:40Z DEBUG ipawinsyncdefaultgroupattr: 2022-12-17T23:55:40Z DEBUG ipaDefaultPrimaryGroup 2022-12-17T23:55:40Z DEBUG ipawinsyncdefaultgroupfilter: 2022-12-17T23:55:40Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2022-12-17T23:55:40Z DEBUG ipawinsyncforcesync: 2022-12-17T23:55:40Z DEBUG true 2022-12-17T23:55:40Z DEBUG ipawinsynchomedirattr: 2022-12-17T23:55:40Z DEBUG ipaHomesRootDir 2022-12-17T23:55:40Z DEBUG ipawinsyncloginshellattr: 2022-12-17T23:55:40Z DEBUG ipaDefaultLoginShell 2022-12-17T23:55:40Z DEBUG ipawinsyncnewentryfilter: 2022-12-17T23:55:40Z DEBUG (cn=ipaConfig) 2022-12-17T23:55:40Z DEBUG ipawinsyncnewuserocattr: 2022-12-17T23:55:40Z DEBUG ipauserobjectclasses 2022-12-17T23:55:40Z DEBUG ipawinsyncrealmattr: 2022-12-17T23:55:40Z DEBUG cn 2022-12-17T23:55:40Z DEBUG ipawinsyncrealmfilter: 2022-12-17T23:55:40Z DEBUG (objectclass=krbRealmContainer) 2022-12-17T23:55:40Z DEBUG ipawinsyncuserattr: 2022-12-17T23:55:40Z DEBUG uidNumber -1 2022-12-17T23:55:40Z DEBUG gidNumber -1 2022-12-17T23:55:40Z DEBUG ipawinsyncuserflatten: 2022-12-17T23:55:40Z DEBUG true 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG ipa winsync plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG ipa-winsync-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG ipa_winsync_plugin_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libipa_winsync 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG preoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG FreeIPA project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG FreeIPA/1.0 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:40Z DEBUG 60 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-dna.update 0.009 sec 2022-12-17T23:55:40Z DEBUG Parsing update file '/usr/share/ipa/updates/20-enable_dirsrv_plugins.update' 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG 7-bit check 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Enforce 7-bit clean attribute values 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG NS7bitAttr 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG NS7bitAttr_Init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libattr-unique-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG betxnpreoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG nsslapd-pluginarg0: 2022-12-17T23:55:40Z DEBUG uid 2022-12-17T23:55:40Z DEBUG nsslapd-pluginarg1: 2022-12-17T23:55:40Z DEBUG mail 2022-12-17T23:55:40Z DEBUG nsslapd-pluginarg2: 2022-12-17T23:55:40Z DEBUG , 2022-12-17T23:55:40Z DEBUG nsslapd-pluginarg3: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG 7-bit check 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Enforce 7-bit clean attribute values 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG NS7bitAttr 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG NS7bitAttr_Init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libattr-unique-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG betxnpreoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG nsslapd-pluginarg0: 2022-12-17T23:55:40Z DEBUG uid 2022-12-17T23:55:40Z DEBUG nsslapd-pluginarg1: 2022-12-17T23:55:40Z DEBUG mail 2022-12-17T23:55:40Z DEBUG nsslapd-pluginarg2: 2022-12-17T23:55:40Z DEBUG , 2022-12-17T23:55:40Z DEBUG nsslapd-pluginarg3: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Account Usability Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Account Usability Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Account Usability Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Account Usability Control plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG Account Usability Control 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG auc_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libacctusability-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG preoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Account Usability Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Account Usability Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Account Usability Control plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG Account Usability Control 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG auc_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libacctusability-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG preoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ACL Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ACL Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ACL Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG acl access check plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG acl 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG acl_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libacl-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG accesscontrol 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ACL Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ACL Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG acl access check plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG acl 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG acl_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libacl-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG accesscontrol 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ACL preoperation,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ACL preoperation,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ACL preoperation 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG acl access check plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG acl 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG acl_preopInit 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libacl-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG preoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ACL preoperation,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ACL preoperation 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG acl access check plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG acl 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG acl_preopInit 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libacl-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG preoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG automemberprocessmodifyops: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Auto Membership Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginConfigArea: 2022-12-17T23:55:40Z DEBUG cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Auto Membership plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG Auto Membership 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG automember_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libautomember-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG betxnpreoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG automemberprocessmodifyops: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Auto Membership Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginConfigArea: 2022-12-17T23:55:40Z DEBUG cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Auto Membership plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG Auto Membership 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG automember_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libautomember-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG betxnpreoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Bitwise Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Bitwise Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Bitwise Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG bitwise match plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG bitwise 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG bitwise_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libbitwise-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG matchingRule 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Bitwise Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Bitwise Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG bitwise match plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG bitwise 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG bitwise_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libbitwise-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG matchingRule 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=chaining database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=chaining database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG chaining database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG LDAP chaining backend database plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG chaining database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG chaining_back_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libchainingdb-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=chaining database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG chaining database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG LDAP chaining backend database plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG chaining database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG chaining_back_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libchainingdb-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Class of Service,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Class of Service,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Class of Service 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:40Z DEBUG State Change Plugin 2022-12-17T23:55:40Z DEBUG Views 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG class of service plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG cos 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG cos_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libcos-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG object 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Class of Service,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Class of Service 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:40Z DEBUG State Change Plugin 2022-12-17T23:55:40Z DEBUG Views 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG class of service plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG cos 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG cos_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libcos-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG object 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=deref,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=deref,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG deref 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Dereference plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG Dereference 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG deref_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libderef-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG preoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=deref,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG deref 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Dereference plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG Dereference 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG deref_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libderef-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG preoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG New entry: cn=HTTP Client,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=HTTP Client,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=HTTP Client,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Internationalization Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Internationalization Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Internationalization Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG internationalized ordering rule plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG orderingrule 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG orderingRule_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libcollation-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG matchingRule 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG nsslapd-pluginarg0: 2022-12-17T23:55:40Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/slapd-collations.conf 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Internationalization Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Internationalization Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG internationalized ordering rule plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG orderingrule 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG orderingRule_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libcollation-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG matchingRule 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG nsslapd-pluginarg0: 2022-12-17T23:55:40Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/slapd-collations.conf 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Linked Attributes,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Linked Attributes 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Linked Attributes plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG Linked Attributes 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG linked_attrs_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG liblinkedattrs-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG betxnpreoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Linked Attributes 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Linked Attributes plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG Linked Attributes 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG linked_attrs_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG liblinkedattrs-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG betxnpreoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Managed Entries 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginConfigArea: 2022-12-17T23:55:40Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Managed Entries plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG Managed Entries 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG mep_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libmanagedentries-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG betxnpreoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Managed Entries 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginConfigArea: 2022-12-17T23:55:40Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Managed Entries plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG Managed Entries 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG mep_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libmanagedentries-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG betxnpreoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG nsContainer 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Multisupplier Replication Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Multisupplier Replication Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Multisupplier Replication Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:40Z DEBUG ldbm database 2022-12-17T23:55:40Z DEBUG AES 2022-12-17T23:55:40Z DEBUG Class of Service 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Multi-supplier Replication Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG replication-multisupplier 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG replication_multisupplier_plugin_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libreplication-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG object 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Multisupplier Replication Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Multisupplier Replication Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:40Z DEBUG ldbm database 2022-12-17T23:55:40Z DEBUG AES 2022-12-17T23:55:40Z DEBUG Class of Service 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG Multi-supplier Replication Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG replication-multisupplier 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG replication_multisupplier_plugin_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libreplication-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG object 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Roles Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Roles Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:40Z DEBUG State Change Plugin 2022-12-17T23:55:40Z DEBUG Views 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG roles plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG roles 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG roles_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libroles-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG object 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Roles Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:40Z DEBUG State Change Plugin 2022-12-17T23:55:40Z DEBUG Views 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG roles plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG roles 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG roles_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libroles-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG object 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Schema Reload,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Schema Reload,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Schema Reload 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG task plugin to reload schema files 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG schemareload 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG schemareload_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libschemareload-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG object 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Schema Reload,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Schema Reload 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG task plugin to reload schema files 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG schemareload 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG schemareload_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libschemareload-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG object 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=State Change Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG State Change Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG state change notification service plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG statechange 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG statechange_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libstatechange-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG betxnpostoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG State Change Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG state change notification service plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG statechange 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG statechange_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libstatechange-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG betxnpostoperation 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=Views,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=Views,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Views 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:40Z DEBUG State Change Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG virtual directory information tree views plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG views 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG views_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libviews-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG object 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=Views,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG Views 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:40Z DEBUG State Change Plugin 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG virtual directory information tree views plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG views 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG views_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libviews-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG object 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=whoami,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG whoami 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG whoami extended operation plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG whoami-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG whoami_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libwhoami-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG extendedop 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG replace: off not found, skipping 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG whoami 2022-12-17T23:55:40Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:40Z DEBUG database 2022-12-17T23:55:40Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:40Z DEBUG whoami extended operation plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:40Z DEBUG on 2022-12-17T23:55:40Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:40Z DEBUG whoami-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:40Z DEBUG whoami_init 2022-12-17T23:55:40Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:40Z DEBUG libwhoami-plugin 2022-12-17T23:55:40Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:40Z DEBUG extendedop 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:40Z DEBUG 389 Project 2022-12-17T23:55:40Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:40Z DEBUG 2.2.4 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsSlapdPlugin 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-enable_dirsrv_plugins.update 0.086 sec 2022-12-17T23:55:40Z DEBUG Parsing update file '/usr/share/ipa/updates/20-host_nis_groups.update' 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG mepTemplateEntry 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG NGP HGP Template 2022-12-17T23:55:40Z DEBUG mepRDNAttr: 2022-12-17T23:55:40Z DEBUG cn 2022-12-17T23:55:40Z DEBUG mepStaticAttr: 2022-12-17T23:55:40Z DEBUG ipaUniqueId: autogenerate 2022-12-17T23:55:40Z DEBUG objectclass: ipanisnetgroup 2022-12-17T23:55:40Z DEBUG objectclass: ipaobject 2022-12-17T23:55:40Z DEBUG nisDomainName: redacted_domain.com 2022-12-17T23:55:40Z DEBUG mepMappedAttr: 2022-12-17T23:55:40Z DEBUG cn: $cn 2022-12-17T23:55:40Z DEBUG memberHost: $dn 2022-12-17T23:55:40Z DEBUG description: ipaNetgroup $cn 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG mepTemplateEntry 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG NGP HGP Template 2022-12-17T23:55:40Z DEBUG mepRDNAttr: 2022-12-17T23:55:40Z DEBUG cn 2022-12-17T23:55:40Z DEBUG mepStaticAttr: 2022-12-17T23:55:40Z DEBUG ipaUniqueId: autogenerate 2022-12-17T23:55:40Z DEBUG objectclass: ipanisnetgroup 2022-12-17T23:55:40Z DEBUG objectclass: ipaobject 2022-12-17T23:55:40Z DEBUG nisDomainName: redacted_domain.com 2022-12-17T23:55:40Z DEBUG mepMappedAttr: 2022-12-17T23:55:40Z DEBUG cn: $cn 2022-12-17T23:55:40Z DEBUG memberHost: $dn 2022-12-17T23:55:40Z DEBUG description: ipaNetgroup $cn 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG NGP Definition 2022-12-17T23:55:40Z DEBUG originScope: 2022-12-17T23:55:40Z DEBUG cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG originFilter: 2022-12-17T23:55:40Z DEBUG objectclass=ipahostgroup 2022-12-17T23:55:40Z DEBUG managedBase: 2022-12-17T23:55:40Z DEBUG cn=ng,cn=alt,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG managedTemplate: 2022-12-17T23:55:40Z DEBUG cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG only: set cn to 'NGP Definition', current value ['NGP Definition'] 2022-12-17T23:55:40Z DEBUG only: updated value ['NGP Definition'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG extensibleObject 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG NGP Definition 2022-12-17T23:55:40Z DEBUG originScope: 2022-12-17T23:55:40Z DEBUG cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG originFilter: 2022-12-17T23:55:40Z DEBUG objectclass=ipahostgroup 2022-12-17T23:55:40Z DEBUG managedBase: 2022-12-17T23:55:40Z DEBUG cn=ng,cn=alt,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG managedTemplate: 2022-12-17T23:55:40Z DEBUG cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-host_nis_groups.update 0.007 sec 2022-12-17T23:55:40Z DEBUG Parsing update file '/usr/share/ipa/updates/20-indices.update' 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG accessRuleType 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'accessRuleType', current value ['accessRuleType'] 2022-12-17T23:55:40Z DEBUG only: updated value ['accessRuleType'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG accessRuleType 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG altSecurityIdentities 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'altSecurityIdentities', current value ['altSecurityIdentities'] 2022-12-17T23:55:40Z DEBUG only: updated value ['altSecurityIdentities'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG altSecurityIdentities 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG automountkey 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'automountkey', current value ['automountkey'] 2022-12-17T23:55:40Z DEBUG only: updated value ['automountkey'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG automountkey 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG automountMapName 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'automountMapName', current value ['automountMapName'] 2022-12-17T23:55:40Z DEBUG only: updated value ['automountMapName'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG automountMapName 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG carLicense 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'carLicense', current value ['carLicense'] 2022-12-17T23:55:40Z DEBUG only: updated value ['carLicense'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG carLicense 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG description 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsindex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'description', current value ['description'] 2022-12-17T23:55:40Z DEBUG only: updated value ['description'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG description 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsindex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG displayname 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'displayname', current value ['displayname'] 2022-12-17T23:55:40Z DEBUG only: updated value ['displayname'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG displayname 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG fqdn 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'fqdn', current value ['fqdn'] 2022-12-17T23:55:40Z DEBUG only: updated value ['fqdn'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG fqdn 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG gidnumber 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsMatchingRule: 2022-12-17T23:55:40Z DEBUG integerOrderingMatch 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'gidnumber', current value ['gidnumber'] 2022-12-17T23:55:40Z DEBUG only: updated value ['gidnumber'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value ['integerOrderingMatch'] 2022-12-17T23:55:40Z DEBUG add: updated value ['integerOrderingMatch'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG gidnumber 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsMatchingRule: 2022-12-17T23:55:40Z DEBUG integerOrderingMatch 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG hostCategory 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'hostCategory', current value ['hostCategory'] 2022-12-17T23:55:40Z DEBUG only: updated value ['hostCategory'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG hostCategory 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG idnsName 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'idnsName', current value ['idnsName'] 2022-12-17T23:55:40Z DEBUG only: updated value ['idnsName'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG idnsName 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaallowedtarget 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaallowedtarget', current value ['ipaallowedtarget'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaallowedtarget'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaallowedtarget 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaAnchorUUID 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaAnchorUUID', current value ['ipaAnchorUUID'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaAnchorUUID'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaAnchorUUID 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaassignedidview 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaassignedidview', current value ['ipaassignedidview'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaassignedidview'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaassignedidview 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaCASubjectDN,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaCASubjectDN,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaCASubjectDN 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaCASubjectDN', current value ['ipaCASubjectDN'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaCASubjectDN'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaCASubjectDN,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaCASubjectDN 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaCertmapData 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaCertmapData', current value ['ipaCertmapData'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaCertmapData'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaCertmapData 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaConfigString 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaConfigString', current value ['ipaConfigString'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaConfigString'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaConfigString 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaEnabledFlag 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaEnabledFlag', current value ['ipaEnabledFlag'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaEnabledFlag'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaEnabledFlag 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaExternalMember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaExternalMember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaExternalMember 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaExternalMember', current value ['ipaExternalMember'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaExternalMember'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaExternalMember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaExternalMember 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaIdpDevAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaIdpDevAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaIdpDevAuthEndpoint 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaIdpDevAuthEndpoint', current value ['ipaIdpDevAuthEndpoint'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaIdpDevAuthEndpoint'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaIdpDevAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaIdpDevAuthEndpoint 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaIdpAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaIdpAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaIdpAuthEndpoint 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaIdpAuthEndpoint', current value ['ipaIdpAuthEndpoint'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaIdpAuthEndpoint'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaIdpAuthEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaIdpAuthEndpoint 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaIdpScope,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaIdpScope,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaIdpScope 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaIdpScope', current value ['ipaIdpScope'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaIdpScope'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaIdpScope,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaIdpScope 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaIdpTokenEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaIdpTokenEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaIdpTokenEndpoint 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaIdpTokenEndpoint', current value ['ipaIdpTokenEndpoint'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaIdpTokenEndpoint'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaIdpTokenEndpoint,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaIdpTokenEndpoint 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaKrbAuthzData 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaKrbAuthzData', current value ['ipaKrbAuthzData'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaKrbAuthzData'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaKrbAuthzData 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipakrbprincipalalias 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipakrbprincipalalias', current value ['ipakrbprincipalalias'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipakrbprincipalalias'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipakrbprincipalalias 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipalocation 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipalocation', current value ['ipalocation'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipalocation'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipalocation 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaMemberCa 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaMemberCa', current value ['ipaMemberCa'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaMemberCa'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaMemberCa 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaMemberCertProfile 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaMemberCertProfile', current value ['ipaMemberCertProfile'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaMemberCertProfile'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaMemberCertProfile 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaNTSecurityIdentifier,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaNTSecurityIdentifier,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaNTSecurityIdentifier 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaNTSecurityIdentifier', current value ['ipaNTSecurityIdentifier'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaNTSecurityIdentifier'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaNTSecurityIdentifier,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaNTSecurityIdentifier 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaNTTrustPartner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaNTTrustPartner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaNTTrustPartner 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaNTTrustPartner', current value ['ipaNTTrustPartner'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaNTTrustPartner'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaNTTrustPartner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaNTTrustPartner 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaOriginalUid 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaOriginalUid', current value ['ipaOriginalUid'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaOriginalUid'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaOriginalUid 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaOwner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaOwner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaOwner 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaOwner', current value ['ipaOwner'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaOwner'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaOwner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaOwner 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipasudorunas 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipasudorunas', current value ['ipasudorunas'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipasudorunas'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipasudorunas 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaSubGidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaSubGidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaSubGidNumber 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsMatchingRule: 2022-12-17T23:55:40Z DEBUG integerOrderingMatch 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaSubGidNumber', current value ['ipaSubGidNumber'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaSubGidNumber'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value ['integerOrderingMatch'] 2022-12-17T23:55:40Z DEBUG add: updated value ['integerOrderingMatch'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaSubGidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaSubGidNumber 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsMatchingRule: 2022-12-17T23:55:40Z DEBUG integerOrderingMatch 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaSubUidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaSubUidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaSubUidNumber 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsMatchingRule: 2022-12-17T23:55:40Z DEBUG integerOrderingMatch 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipaSubUidNumber', current value ['ipaSubUidNumber'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipaSubUidNumber'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value ['integerOrderingMatch'] 2022-12-17T23:55:40Z DEBUG add: updated value ['integerOrderingMatch'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaSubUidNumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaSubUidNumber 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsMatchingRule: 2022-12-17T23:55:40Z DEBUG integerOrderingMatch 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=sudoorder,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=sudoorder,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG sudoorder 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsMatchingRule: 2022-12-17T23:55:40Z DEBUG integerOrderingMatch 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'sudoorder', current value ['sudoorder'] 2022-12-17T23:55:40Z DEBUG only: updated value ['sudoorder'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value ['integerOrderingMatch'] 2022-12-17T23:55:40Z DEBUG add: updated value ['integerOrderingMatch'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=sudoorder,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG sudoorder 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsMatchingRule: 2022-12-17T23:55:40Z DEBUG integerOrderingMatch 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipasudorunasgroup 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipasudorunasgroup', current value ['ipasudorunasgroup'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipasudorunasgroup'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipasudorunasgroup 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipatokenradiusconfiglink 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipatokenradiusconfiglink', current value ['ipatokenradiusconfiglink'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipatokenradiusconfiglink'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipatokenradiusconfiglink 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipauniqueid 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipauniqueid', current value ['ipauniqueid'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipauniqueid'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipauniqueid 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipServicePort 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ipServicePort', current value ['ipServicePort'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ipServicePort'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipServicePort 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG krbCanonicalName 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'krbCanonicalName', current value ['krbCanonicalName'] 2022-12-17T23:55:40Z DEBUG only: updated value ['krbCanonicalName'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG krbCanonicalName 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=krbPasswordExpiration,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=krbPasswordExpiration,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG krbPasswordExpiration 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'krbPasswordExpiration', current value ['krbPasswordExpiration'] 2022-12-17T23:55:40Z DEBUG only: updated value ['krbPasswordExpiration'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=krbPasswordExpiration,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG krbPasswordExpiration 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG krbPrincipalName 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsMatchingRule: 2022-12-17T23:55:40Z DEBUG caseIgnoreIA5Match 2022-12-17T23:55:40Z DEBUG caseExactIA5Match 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'krbPrincipalName', current value ['krbPrincipalName'] 2022-12-17T23:55:40Z DEBUG only: updated value ['krbPrincipalName'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: 'caseIgnoreIA5Match' to nsMatchingRule, current value ['caseIgnoreIA5Match', 'caseExactIA5Match'] 2022-12-17T23:55:40Z DEBUG add: updated value ['caseExactIA5Match', 'caseIgnoreIA5Match'] 2022-12-17T23:55:40Z DEBUG add: 'caseExactIA5Match' to nsMatchingRule, current value ['caseExactIA5Match', 'caseIgnoreIA5Match'] 2022-12-17T23:55:40Z DEBUG add: updated value ['caseIgnoreIA5Match', 'caseExactIA5Match'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG krbPrincipalName 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsMatchingRule: 2022-12-17T23:55:40Z DEBUG caseIgnoreIA5Match 2022-12-17T23:55:40Z DEBUG caseExactIA5Match 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG l 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsindex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'l', current value ['l'] 2022-12-17T23:55:40Z DEBUG only: updated value ['l'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG l 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsindex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG macAddress 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'macAddress', current value ['macAddress'] 2022-12-17T23:55:40Z DEBUG only: updated value ['macAddress'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG macAddress 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG managedby 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'managedby', current value ['managedby'] 2022-12-17T23:55:40Z DEBUG only: updated value ['managedby'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG managedby 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG manager 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'manager', current value ['manager'] 2022-12-17T23:55:40Z DEBUG only: updated value ['manager'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG manager 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG member 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG only: set cn to 'member', current value ['member'] 2022-12-17T23:55:40Z DEBUG only: updated value ['member'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG member 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberallowcmd 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'memberallowcmd', current value ['memberallowcmd'] 2022-12-17T23:55:40Z DEBUG only: updated value ['memberallowcmd'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberallowcmd 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberdenycmd 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'memberdenycmd', current value ['memberdenycmd'] 2022-12-17T23:55:40Z DEBUG only: updated value ['memberdenycmd'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberdenycmd 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberHost 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'memberHost', current value ['memberHost'] 2022-12-17T23:55:40Z DEBUG only: updated value ['memberHost'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberHost 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberManager 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'memberManager', current value ['memberManager'] 2022-12-17T23:55:40Z DEBUG only: updated value ['memberManager'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberManager 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberOf 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG only: set cn to 'memberOf', current value ['memberOf'] 2022-12-17T23:55:40Z DEBUG only: updated value ['memberOf'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberOf 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=memberPrincipal,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=memberPrincipal,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberPrincipal 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'memberPrincipal', current value ['memberPrincipal'] 2022-12-17T23:55:40Z DEBUG only: updated value ['memberPrincipal'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=memberPrincipal,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberPrincipal 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberservice 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'memberservice', current value ['memberservice'] 2022-12-17T23:55:40Z DEBUG only: updated value ['memberservice'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberservice 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberuid 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'memberuid', current value ['memberuid'] 2022-12-17T23:55:40Z DEBUG only: updated value ['memberuid'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberuid 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberUser 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'memberUser', current value ['memberUser'] 2022-12-17T23:55:40Z DEBUG only: updated value ['memberUser'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG memberUser 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG nsHardwarePlatform 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsindex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'nsHardwarePlatform', current value ['nsHardwarePlatform'] 2022-12-17T23:55:40Z DEBUG only: updated value ['nsHardwarePlatform'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG nsHardwarePlatform 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsindex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG nsHostLocation 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsindex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'nsHostLocation', current value ['nsHostLocation'] 2022-12-17T23:55:40Z DEBUG only: updated value ['nsHostLocation'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG nsHostLocation 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsindex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG nsOsVersion 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsindex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'nsOsVersion', current value ['nsOsVersion'] 2022-12-17T23:55:40Z DEBUG only: updated value ['nsOsVersion'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG nsOsVersion 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsindex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ntUniqueId 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG only: set cn to 'ntUniqueId', current value ['ntUniqueId'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ntUniqueId'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ntUniqueId 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ntUserDomainId 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG only: set cn to 'ntUserDomainId', current value ['ntUserDomainId'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ntUserDomainId'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ntUserDomainId 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ou 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'ou', current value ['ou'] 2022-12-17T23:55:40Z DEBUG only: updated value ['ou'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ou 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG owner 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG only: set cn to 'owner', current value ['owner'] 2022-12-17T23:55:40Z DEBUG only: updated value ['owner'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG owner 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG secretary 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'secretary', current value ['secretary'] 2022-12-17T23:55:40Z DEBUG only: updated value ['secretary'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG secretary 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG seealso 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG only: set cn to 'seealso', current value ['seealso'] 2022-12-17T23:55:40Z DEBUG only: updated value ['seealso'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG seealso 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG serverhostname 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'serverhostname', current value ['serverhostname'] 2022-12-17T23:55:40Z DEBUG only: updated value ['serverhostname'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG serverhostname 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG sourcehost 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'sourcehost', current value ['sourcehost'] 2022-12-17T23:55:40Z DEBUG only: updated value ['sourcehost'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG sourcehost 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG title 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'title', current value ['title'] 2022-12-17T23:55:40Z DEBUG only: updated value ['title'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG title 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG uid 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG only: set cn to 'uid', current value ['uid'] 2022-12-17T23:55:40Z DEBUG only: updated value ['uid'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG uid 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG uidnumber 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsMatchingRule: 2022-12-17T23:55:40Z DEBUG integerOrderingMatch 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'uidnumber', current value ['uidnumber'] 2022-12-17T23:55:40Z DEBUG only: updated value ['uidnumber'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:40Z DEBUG add: 'integerOrderingMatch' to nsMatchingRule, current value ['integerOrderingMatch'] 2022-12-17T23:55:40Z DEBUG add: updated value ['integerOrderingMatch'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG uidnumber 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG nsMatchingRule: 2022-12-17T23:55:40Z DEBUG integerOrderingMatch 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG uniquemember 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG only: set cn to 'uniquemember', current value ['uniquemember'] 2022-12-17T23:55:40Z DEBUG only: updated value ['uniquemember'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG add: updated value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'sub' to nsIndexType, current value ['sub', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'sub'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG uniquemember 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG sub 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG userCertificate 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG only: set cn to 'userCertificate', current value ['userCertificate'] 2022-12-17T23:55:40Z DEBUG only: updated value ['userCertificate'] 2022-12-17T23:55:40Z DEBUG add: 'eq' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG add: updated value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: 'pres' to nsIndexType, current value ['pres', 'eq'] 2022-12-17T23:55:40Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG userCertificate 2022-12-17T23:55:40Z DEBUG nsIndexType: 2022-12-17T23:55:40Z DEBUG eq 2022-12-17T23:55:40Z DEBUG pres 2022-12-17T23:55:40Z DEBUG nsSystemIndex: 2022-12-17T23:55:40Z DEBUG false 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG nsIndex 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-indices.update 0.239 sec 2022-12-17T23:55:40Z DEBUG Parsing update file '/usr/share/ipa/updates/20-ipaservers_hostgroup.update' 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG groupOfNames 2022-12-17T23:55:40Z DEBUG nestedGroup 2022-12-17T23:55:40Z DEBUG ipaobject 2022-12-17T23:55:40Z DEBUG ipahostgroup 2022-12-17T23:55:40Z DEBUG description: 2022-12-17T23:55:40Z DEBUG IPA server hosts 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaservers 2022-12-17T23:55:40Z DEBUG ipaUniqueID: 2022-12-17T23:55:40Z DEBUG ad2291bc-7e65-11ed-9994-525400000010 2022-12-17T23:55:40Z DEBUG member: 2022-12-17T23:55:40Z DEBUG fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG groupOfNames 2022-12-17T23:55:40Z DEBUG nestedGroup 2022-12-17T23:55:40Z DEBUG ipaobject 2022-12-17T23:55:40Z DEBUG ipahostgroup 2022-12-17T23:55:40Z DEBUG description: 2022-12-17T23:55:40Z DEBUG IPA server hosts 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaservers 2022-12-17T23:55:40Z DEBUG ipaUniqueID: 2022-12-17T23:55:40Z DEBUG ad2291bc-7e65-11ed-9994-525400000010 2022-12-17T23:55:40Z DEBUG member: 2022-12-17T23:55:40Z DEBUG fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG groupOfNames 2022-12-17T23:55:40Z DEBUG nestedGroup 2022-12-17T23:55:40Z DEBUG ipaobject 2022-12-17T23:55:40Z DEBUG ipahostgroup 2022-12-17T23:55:40Z DEBUG description: 2022-12-17T23:55:40Z DEBUG IPA server hosts 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaservers 2022-12-17T23:55:40Z DEBUG ipaUniqueID: 2022-12-17T23:55:40Z DEBUG ad2291bc-7e65-11ed-9994-525400000010 2022-12-17T23:55:40Z DEBUG member: 2022-12-17T23:55:40Z DEBUG fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG add: 'fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com' to member, current value ['fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:40Z DEBUG add: updated value ['fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG groupOfNames 2022-12-17T23:55:40Z DEBUG nestedGroup 2022-12-17T23:55:40Z DEBUG ipaobject 2022-12-17T23:55:40Z DEBUG ipahostgroup 2022-12-17T23:55:40Z DEBUG description: 2022-12-17T23:55:40Z DEBUG IPA server hosts 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG ipaservers 2022-12-17T23:55:40Z DEBUG ipaUniqueID: 2022-12-17T23:55:40Z DEBUG ad2291bc-7e65-11ed-9994-525400000010 2022-12-17T23:55:40Z DEBUG member: 2022-12-17T23:55:40Z DEBUG fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG [] 2022-12-17T23:55:40Z DEBUG Updated 0 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-ipaservers_hostgroup.update 0.008 sec 2022-12-17T23:55:40Z DEBUG Parsing update file '/usr/share/ipa/updates/20-nss_ldap.update' 2022-12-17T23:55:40Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG add: 'domain' to objectClass, current value ['top', 'domain', 'pilotObject'] 2022-12-17T23:55:40Z DEBUG add: updated value ['top', 'pilotObject', 'domain'] 2022-12-17T23:55:40Z DEBUG add: 'domainRelatedObject' to objectClass, current value ['top', 'pilotObject', 'domain'] 2022-12-17T23:55:40Z DEBUG add: updated value ['top', 'pilotObject', 'domain', 'domainRelatedObject'] 2022-12-17T23:55:40Z DEBUG add: 'nisDomainObject' to objectClass, current value ['top', 'pilotObject', 'domain', 'domainRelatedObject'] 2022-12-17T23:55:40Z DEBUG add: updated value ['top', 'pilotObject', 'domain', 'domainRelatedObject', 'nisDomainObject'] 2022-12-17T23:55:40Z DEBUG add: 'redacted_domain.com' to associatedDomain, current value [] 2022-12-17T23:55:40Z DEBUG add: updated value ['redacted_domain.com'] 2022-12-17T23:55:40Z DEBUG add: 'redacted_domain.com' to nisDomain, current value [] 2022-12-17T23:55:40Z DEBUG add: updated value ['redacted_domain.com'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG pilotObject 2022-12-17T23:55:40Z DEBUG domain 2022-12-17T23:55:40Z DEBUG domainRelatedObject 2022-12-17T23:55:40Z DEBUG nisDomainObject 2022-12-17T23:55:40Z DEBUG dc: 2022-12-17T23:55:40Z DEBUG redacted_domain 2022-12-17T23:55:40Z DEBUG info: 2022-12-17T23:55:40Z DEBUG IPA V2.0 2022-12-17T23:55:40Z DEBUG aci: 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:40Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:40Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:40Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:40Z DEBUG associatedDomain: 2022-12-17T23:55:40Z DEBUG redacted_domain.com 2022-12-17T23:55:40Z DEBUG nisDomain: 2022-12-17T23:55:40Z DEBUG redacted_domain.com 2022-12-17T23:55:40Z DEBUG [(2, 'associatedDomain', ['redacted_domain.com']), (2, 'nisDomain', ['redacted_domain.com']), (0, 'objectClass', ['domainRelatedObject', 'nisDomainObject'])] 2022-12-17T23:55:40Z DEBUG Updated 1 2022-12-17T23:55:40Z DEBUG update_entry modlist [(2, 'associatedDomain', [b'redacted_domain.com']), (2, 'nisDomain', [b'redacted_domain.com']), (0, 'objectClass', [b'domainRelatedObject', b'nisDomainObject'])] 2022-12-17T23:55:40Z DEBUG Done 2022-12-17T23:55:40Z DEBUG New entry: ou=profile,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: ou=profile,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG add: 'top' to objectClass, current value [] 2022-12-17T23:55:40Z DEBUG add: updated value ['top'] 2022-12-17T23:55:40Z DEBUG add: 'organizationalUnit' to objectClass, current value ['top'] 2022-12-17T23:55:40Z DEBUG add: updated value ['top', 'organizationalUnit'] 2022-12-17T23:55:40Z DEBUG add: 'profiles' to ou, current value [] 2022-12-17T23:55:40Z DEBUG add: updated value ['profiles'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: ou=profile,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG organizationalUnit 2022-12-17T23:55:40Z DEBUG ou: 2022-12-17T23:55:40Z DEBUG profiles 2022-12-17T23:55:40Z DEBUG New entry: cn=default,ou=profile,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=default,ou=profile,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG ObjectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG DUAConfigProfile 2022-12-17T23:55:40Z DEBUG defaultServerList: 2022-12-17T23:55:40Z DEBUG master.redacted_domain.com 2022-12-17T23:55:40Z DEBUG defaultSearchBase: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG authenticationMethod: 2022-12-17T23:55:40Z DEBUG none 2022-12-17T23:55:40Z DEBUG searchTimeLimit: 2022-12-17T23:55:40Z DEBUG 15 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG default 2022-12-17T23:55:40Z DEBUG serviceSearchDescriptor: 2022-12-17T23:55:40Z DEBUG passwd:cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG group:cn=groups,cn=compat,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG bindTimeLimit: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG objectClassMap: 2022-12-17T23:55:40Z DEBUG shadow:shadowAccount=posixAccount 2022-12-17T23:55:40Z DEBUG followReferrals: 2022-12-17T23:55:40Z DEBUG TRUE 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=default,ou=profile,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG ObjectClass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG DUAConfigProfile 2022-12-17T23:55:40Z DEBUG defaultServerList: 2022-12-17T23:55:40Z DEBUG master.redacted_domain.com 2022-12-17T23:55:40Z DEBUG defaultSearchBase: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG authenticationMethod: 2022-12-17T23:55:40Z DEBUG none 2022-12-17T23:55:40Z DEBUG searchTimeLimit: 2022-12-17T23:55:40Z DEBUG 15 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG default 2022-12-17T23:55:40Z DEBUG serviceSearchDescriptor: 2022-12-17T23:55:40Z DEBUG passwd:cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG group:cn=groups,cn=compat,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG bindTimeLimit: 2022-12-17T23:55:40Z DEBUG 5 2022-12-17T23:55:40Z DEBUG objectClassMap: 2022-12-17T23:55:40Z DEBUG shadow:shadowAccount=posixAccount 2022-12-17T23:55:40Z DEBUG followReferrals: 2022-12-17T23:55:40Z DEBUG TRUE 2022-12-17T23:55:40Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-nss_ldap.update 0.079 sec 2022-12-17T23:55:40Z DEBUG Parsing update file '/usr/share/ipa/updates/20-replication.update' 2022-12-17T23:55:40Z DEBUG New entry: cn=replication,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=replication,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG nsDS5Replica 2022-12-17T23:55:40Z DEBUG nsDS5ReplicaId: 2022-12-17T23:55:40Z DEBUG 3 2022-12-17T23:55:40Z DEBUG nsDS5ReplicaRoot: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=replication,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG nsDS5Replica 2022-12-17T23:55:40Z DEBUG nsDS5ReplicaId: 2022-12-17T23:55:40Z DEBUG 3 2022-12-17T23:55:40Z DEBUG nsDS5ReplicaRoot: 2022-12-17T23:55:40Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG New entry: cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Initial value 2022-12-17T23:55:40Z DEBUG dn: cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG groupofnames 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG replication managers 2022-12-17T23:55:40Z DEBUG add: 'krbprincipalname=ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:40Z DEBUG add: updated value ['krbprincipalname=ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:40Z DEBUG --------------------------------------------- 2022-12-17T23:55:40Z DEBUG Final value after applying updates 2022-12-17T23:55:40Z DEBUG dn: cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:40Z DEBUG objectclass: 2022-12-17T23:55:40Z DEBUG top 2022-12-17T23:55:40Z DEBUG groupofnames 2022-12-17T23:55:40Z DEBUG cn: 2022-12-17T23:55:40Z DEBUG replication managers 2022-12-17T23:55:40Z DEBUG member: 2022-12-17T23:55:40Z DEBUG krbprincipalname=ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG topology 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG topology 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=domain,cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=domain,cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG iparepltopoconf 2022-12-17T23:55:41Z DEBUG ipaReplTopoConfRoot: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsDS5ReplicatedAttributeList: 2022-12-17T23:55:41Z DEBUG (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime 2022-12-17T23:55:41Z DEBUG nsDS5ReplicatedAttributeListTotal: 2022-12-17T23:55:41Z DEBUG (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime 2022-12-17T23:55:41Z DEBUG nsds5ReplicaStripAttrs: 2022-12-17T23:55:41Z DEBUG modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG domain 2022-12-17T23:55:41Z DEBUG add: '(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime' to nsDS5ReplicatedAttributeList, current value ['(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime'] 2022-12-17T23:55:41Z DEBUG add: updated value ['(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime'] 2022-12-17T23:55:41Z DEBUG add: '(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime' to nsDS5ReplicatedAttributeListTotal, current value ['(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime'] 2022-12-17T23:55:41Z DEBUG add: updated value ['(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime'] 2022-12-17T23:55:41Z DEBUG add: 'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp' to nsds5ReplicaStripAttrs, current value ['modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'] 2022-12-17T23:55:41Z DEBUG add: updated value ['modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=domain,cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG iparepltopoconf 2022-12-17T23:55:41Z DEBUG ipaReplTopoConfRoot: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsDS5ReplicatedAttributeList: 2022-12-17T23:55:41Z DEBUG (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime 2022-12-17T23:55:41Z DEBUG nsDS5ReplicatedAttributeListTotal: 2022-12-17T23:55:41Z DEBUG (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount passwordgraceusertime 2022-12-17T23:55:41Z DEBUG nsds5ReplicaStripAttrs: 2022-12-17T23:55:41Z DEBUG modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG domain 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Deleting entry cn=realm,cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG cn=realm,cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com did not exist:no such entry 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=master.redacted_domain.com,cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=master.redacted_domain.com,cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG ipaReplTopoManagedServer 2022-12-17T23:55:41Z DEBUG ipaConfigObject 2022-12-17T23:55:41Z DEBUG ipaSupportedDomainLevelConfig 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG master.redacted_domain.com 2022-12-17T23:55:41Z DEBUG ipaReplTopoManagedSuffix: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG ipaMinDomainLevel: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG ipaMaxDomainLevel: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG add: 'ipaReplTopoManagedServer' to objectclass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2022-12-17T23:55:41Z DEBUG add: updated value ['top', 'nsContainer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig', 'ipaReplTopoManagedServer'] 2022-12-17T23:55:41Z DEBUG add: 'dc=redacted_domain,dc=com' to ipaReplTopoManagedSuffix, current value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG add: updated value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=master.redacted_domain.com,cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG ipaConfigObject 2022-12-17T23:55:41Z DEBUG ipaSupportedDomainLevelConfig 2022-12-17T23:55:41Z DEBUG ipaReplTopoManagedServer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG master.redacted_domain.com 2022-12-17T23:55:41Z DEBUG ipaReplTopoManagedSuffix: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG ipaMinDomainLevel: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG ipaMaxDomainLevel: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=IPA Topology Configuration,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=IPA Topology Configuration,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG IPA Topology Configuration 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:41Z DEBUG ldbm database 2022-12-17T23:55:41Z DEBUG Multisupplier Replication Plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG ipa-topology-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG ipa-topology-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG ipa_topo_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libtopology 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG object 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG freeipa 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG 1.0 2022-12-17T23:55:41Z DEBUG nsslapd-topo-plugin-shared-binddngroup: 2022-12-17T23:55:41Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-topo-plugin-shared-config-base: 2022-12-17T23:55:41Z DEBUG cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-topo-plugin-shared-replica-root: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG o=ipaca 2022-12-17T23:55:41Z DEBUG nsslapd-topo-plugin-startup-delay: 2022-12-17T23:55:41Z DEBUG 20 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=IPA Topology Configuration,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG IPA Topology Configuration 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:41Z DEBUG ldbm database 2022-12-17T23:55:41Z DEBUG Multisupplier Replication Plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG ipa-topology-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG ipa-topology-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG ipa_topo_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libtopology 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG object 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG freeipa 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG 1.0 2022-12-17T23:55:41Z DEBUG nsslapd-topo-plugin-shared-binddngroup: 2022-12-17T23:55:41Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-topo-plugin-shared-config-base: 2022-12-17T23:55:41Z DEBUG cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-topo-plugin-shared-replica-root: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG o=ipaca 2022-12-17T23:55:41Z DEBUG nsslapd-topo-plugin-startup-delay: 2022-12-17T23:55:41Z DEBUG 20 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-replication.update 0.040 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/20-sslciphers.update' 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=encryption,cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=encryption,cn=config 2022-12-17T23:55:41Z DEBUG CACertExtractFile: 2022-12-17T23:55:41Z DEBUG /tmp/slapd-REDACTED_DOMAIN-COM/REDACTED_DOMAIN.COM20IPA20CA.pem 2022-12-17T23:55:41Z DEBUG allowWeakCipher: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG encryption 2022-12-17T23:55:41Z DEBUG nsSSL3Ciphers: 2022-12-17T23:55:41Z DEBUG default 2022-12-17T23:55:41Z DEBUG nsSSLClientAuth: 2022-12-17T23:55:41Z DEBUG allowed 2022-12-17T23:55:41Z DEBUG nsSSLSessionTimeout: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsEncryptionConfig 2022-12-17T23:55:41Z DEBUG nsSSLSupportedCiphers: 2022-12-17T23:55:41Z DEBUG TLS_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2022-12-17T23:55:41Z DEBUG TLS_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA::AES::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA::AES::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_RC4_128_SHA::RC4::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_ECDH_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_ECDH_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2022-12-17T23:55:41Z DEBUG TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2022-12-17T23:55:41Z DEBUG TLS_ECDH_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_ECDH_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_SEED_CBC_SHA::SEED::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_RC4_128_MD5::RC4::MD5::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_DES_CBC_SHA::DES::SHA1::64 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_NULL_SHA::NULL::SHA1::0 2022-12-17T23:55:41Z DEBUG TLS_ECDH_RSA_WITH_NULL_SHA::NULL::SHA1::0 2022-12-17T23:55:41Z DEBUG TLS_ECDH_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_NULL_SHA::NULL::SHA1::0 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_NULL_SHA256::NULL::SHA256::0 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_NULL_MD5::NULL::MD5::0 2022-12-17T23:55:41Z DEBUG only: set nsSSL3Ciphers to 'default', current value ['default'] 2022-12-17T23:55:41Z DEBUG only: updated value ['default'] 2022-12-17T23:55:41Z DEBUG addifnew: 'off' to allowWeakCipher, current value ['off'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=encryption,cn=config 2022-12-17T23:55:41Z DEBUG CACertExtractFile: 2022-12-17T23:55:41Z DEBUG /tmp/slapd-REDACTED_DOMAIN-COM/REDACTED_DOMAIN.COM20IPA20CA.pem 2022-12-17T23:55:41Z DEBUG allowWeakCipher: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG encryption 2022-12-17T23:55:41Z DEBUG nsSSL3Ciphers: 2022-12-17T23:55:41Z DEBUG default 2022-12-17T23:55:41Z DEBUG nsSSLClientAuth: 2022-12-17T23:55:41Z DEBUG allowed 2022-12-17T23:55:41Z DEBUG nsSSLSessionTimeout: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsEncryptionConfig 2022-12-17T23:55:41Z DEBUG nsSSLSupportedCiphers: 2022-12-17T23:55:41Z DEBUG TLS_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2022-12-17T23:55:41Z DEBUG TLS_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA::AES::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA::AES::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_RC4_128_SHA::RC4::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_ECDH_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_ECDH_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2022-12-17T23:55:41Z DEBUG TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2022-12-17T23:55:41Z DEBUG TLS_ECDH_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_ECDH_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_SEED_CBC_SHA::SEED::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_RC4_128_MD5::RC4::MD5::128 2022-12-17T23:55:41Z DEBUG TLS_DHE_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2022-12-17T23:55:41Z DEBUG TLS_DHE_DSS_WITH_DES_CBC_SHA::DES::SHA1::64 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2022-12-17T23:55:41Z DEBUG TLS_ECDHE_RSA_WITH_NULL_SHA::NULL::SHA1::0 2022-12-17T23:55:41Z DEBUG TLS_ECDH_RSA_WITH_NULL_SHA::NULL::SHA1::0 2022-12-17T23:55:41Z DEBUG TLS_ECDH_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_NULL_SHA::NULL::SHA1::0 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_NULL_SHA256::NULL::SHA256::0 2022-12-17T23:55:41Z DEBUG TLS_RSA_WITH_NULL_MD5::NULL::MD5::0 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-sslciphers.update 0.015 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/20-syncrepl.update' 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=Retro Changelog Plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Retro Changelog Plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Retro Changelog Plugin 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:41Z DEBUG Class of Service 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:41Z DEBUG database 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG retrocl_plugin_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libretrocl-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG object 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:41Z DEBUG 25 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG only: set nsslapd-pluginEnabled to 'on', current value ['off'] 2022-12-17T23:55:41Z DEBUG only: updated value ['on'] 2022-12-17T23:55:41Z DEBUG add: 'nsuniqueid:targetUniqueId' to nsslapd-attribute, current value [] 2022-12-17T23:55:41Z DEBUG add: updated value ['nsuniqueid:targetUniqueId'] 2022-12-17T23:55:41Z DEBUG add: '2d' to nsslapd-changelogmaxage, current value [] 2022-12-17T23:55:41Z DEBUG add: updated value ['2d'] 2022-12-17T23:55:41Z DEBUG add: 'cn=dns,dc=redacted_domain,dc=com' to nsslapd-include-suffix, current value [] 2022-12-17T23:55:41Z DEBUG add: updated value ['cn=dns,dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Retro Changelog Plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Retro Changelog Plugin 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:41Z DEBUG Class of Service 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:41Z DEBUG database 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG retrocl_plugin_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libretrocl-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG object 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:41Z DEBUG 25 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG nsslapd-attribute: 2022-12-17T23:55:41Z DEBUG nsuniqueid:targetUniqueId 2022-12-17T23:55:41Z DEBUG nsslapd-changelogmaxage: 2022-12-17T23:55:41Z DEBUG 2d 2022-12-17T23:55:41Z DEBUG nsslapd-include-suffix: 2022-12-17T23:55:41Z DEBUG cn=dns,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG [(2, 'nsslapd-pluginEnabled', ['on']), (2, 'nsslapd-attribute', ['nsuniqueid:targetUniqueId']), (2, 'nsslapd-include-suffix', ['cn=dns,dc=redacted_domain,dc=com']), (2, 'nsslapd-changelogmaxage', ['2d'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(2, 'nsslapd-pluginEnabled', [b'on']), (2, 'nsslapd-attribute', [b'nsuniqueid:targetUniqueId']), (2, 'nsslapd-include-suffix', [b'cn=dns,dc=redacted_domain,dc=com']), (2, 'nsslapd-changelogmaxage', [b'2d'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG MemberOf Plugin 2022-12-17T23:55:41Z DEBUG memberofattr: 2022-12-17T23:55:41Z DEBUG memberOf 2022-12-17T23:55:41Z DEBUG memberofgroupattr: 2022-12-17T23:55:41Z DEBUG member 2022-12-17T23:55:41Z DEBUG memberUser 2022-12-17T23:55:41Z DEBUG memberHost 2022-12-17T23:55:41Z DEBUG ipaOwner 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:41Z DEBUG database 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG memberof plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG memberof 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG memberof_postop_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libmemberof-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG betxnpostoperation 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG 389 Project 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG 2.2.4 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG add: 'dc=redacted_domain,dc=com' to memberofentryscope, current value [] 2022-12-17T23:55:41Z DEBUG add: updated value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG add: 'cn=compat,dc=redacted_domain,dc=com' to memberofentryscopeexcludesubtree, current value [] 2022-12-17T23:55:41Z DEBUG add: updated value ['cn=compat,dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG add: 'cn=provisioning,dc=redacted_domain,dc=com' to memberofentryscopeexcludesubtree, current value ['cn=compat,dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG add: updated value ['cn=compat,dc=redacted_domain,dc=com', 'cn=provisioning,dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com' to memberofentryscopeexcludesubtree, current value ['cn=compat,dc=redacted_domain,dc=com', 'cn=provisioning,dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG add: updated value ['cn=compat,dc=redacted_domain,dc=com', 'cn=provisioning,dc=redacted_domain,dc=com', 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG MemberOf Plugin 2022-12-17T23:55:41Z DEBUG memberofattr: 2022-12-17T23:55:41Z DEBUG memberOf 2022-12-17T23:55:41Z DEBUG memberofgroupattr: 2022-12-17T23:55:41Z DEBUG member 2022-12-17T23:55:41Z DEBUG memberUser 2022-12-17T23:55:41Z DEBUG memberHost 2022-12-17T23:55:41Z DEBUG ipaOwner 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:41Z DEBUG database 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG memberof plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG memberof 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG memberof_postop_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libmemberof-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG betxnpostoperation 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG 389 Project 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG 2.2.4 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG memberofentryscope: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG memberofentryscopeexcludesubtree: 2022-12-17T23:55:41Z DEBUG cn=compat,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG [(2, 'memberofentryscopeexcludesubtree', ['cn=compat,dc=redacted_domain,dc=com', 'cn=provisioning,dc=redacted_domain,dc=com', 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com']), (2, 'memberofentryscope', ['dc=redacted_domain,dc=com'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(2, 'memberofentryscopeexcludesubtree', [b'cn=compat,dc=redacted_domain,dc=com', b'cn=provisioning,dc=redacted_domain,dc=com', b'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com']), (2, 'memberofentryscope', [b'dc=redacted_domain,dc=com'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG referential integrity postoperation 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:41Z DEBUG database 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG referential integrity plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG referint 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG referint_postop_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libreferint-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG betxnpostoperation 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG 389 Project 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG 2.2.4 2022-12-17T23:55:41Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:41Z DEBUG 40 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG referint-logfile: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/referint 2022-12-17T23:55:41Z DEBUG referint-membership-attr: 2022-12-17T23:55:41Z DEBUG member 2022-12-17T23:55:41Z DEBUG uniquemember 2022-12-17T23:55:41Z DEBUG owner 2022-12-17T23:55:41Z DEBUG seeAlso 2022-12-17T23:55:41Z DEBUG referint-update-delay: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG add: 'dc=redacted_domain,dc=com' to nsslapd-plugincontainerscope, current value [] 2022-12-17T23:55:41Z DEBUG add: updated value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG add: 'dc=redacted_domain,dc=com' to nsslapd-pluginentryscope, current value [] 2022-12-17T23:55:41Z DEBUG add: updated value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG add: 'cn=provisioning,dc=redacted_domain,dc=com' to nsslapd-pluginExcludeEntryScope, current value [] 2022-12-17T23:55:41Z DEBUG add: updated value ['cn=provisioning,dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG referential integrity postoperation 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:41Z DEBUG database 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG referential integrity plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG referint 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG referint_postop_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libreferint-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG betxnpostoperation 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG 389 Project 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG 2.2.4 2022-12-17T23:55:41Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:41Z DEBUG 40 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG referint-logfile: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/referint 2022-12-17T23:55:41Z DEBUG referint-membership-attr: 2022-12-17T23:55:41Z DEBUG member 2022-12-17T23:55:41Z DEBUG uniquemember 2022-12-17T23:55:41Z DEBUG owner 2022-12-17T23:55:41Z DEBUG seeAlso 2022-12-17T23:55:41Z DEBUG referint-update-delay: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-plugincontainerscope: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-pluginentryscope: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-pluginExcludeEntryScope: 2022-12-17T23:55:41Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG [(2, 'nsslapd-pluginentryscope', ['dc=redacted_domain,dc=com']), (2, 'nsslapd-plugincontainerscope', ['dc=redacted_domain,dc=com']), (2, 'nsslapd-pluginExcludeEntryScope', ['cn=provisioning,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(2, 'nsslapd-pluginentryscope', [b'dc=redacted_domain,dc=com']), (2, 'nsslapd-plugincontainerscope', [b'dc=redacted_domain,dc=com']), (2, 'nsslapd-pluginExcludeEntryScope', [b'cn=provisioning,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=Content Synchronization,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Content Synchronization,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Content Synchronization 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:41Z DEBUG Retro Changelog Plugin 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:41Z DEBUG database 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG sync_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libcontentsync-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG object 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG only: set nsslapd-pluginEnabled to 'on', current value ['off'] 2022-12-17T23:55:41Z DEBUG only: updated value ['on'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Content Synchronization,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Content Synchronization 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-named: 2022-12-17T23:55:41Z DEBUG Retro Changelog Plugin 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:41Z DEBUG database 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG sync_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libcontentsync-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG object 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG [(2, 'nsslapd-pluginEnabled', ['on'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(2, 'nsslapd-pluginEnabled', [b'on'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG IPA Unique IDs 2022-12-17T23:55:41Z DEBUG ipauuidattr: 2022-12-17T23:55:41Z DEBUG ipaUniqueID 2022-12-17T23:55:41Z DEBUG ipauuidenforce: 2022-12-17T23:55:41Z DEBUG TRUE 2022-12-17T23:55:41Z DEBUG ipauuidfilter: 2022-12-17T23:55:41Z DEBUG (|(objectclass=ipaObject)(objectclass=ipaAssociation)) 2022-12-17T23:55:41Z DEBUG ipauuidmagicregen: 2022-12-17T23:55:41Z DEBUG autogenerate 2022-12-17T23:55:41Z DEBUG ipauuidscope: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG add: 'cn=provisioning,dc=redacted_domain,dc=com' to ipaUuidExcludeSubtree, current value [] 2022-12-17T23:55:41Z DEBUG add: updated value ['cn=provisioning,dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG IPA Unique IDs 2022-12-17T23:55:41Z DEBUG ipauuidattr: 2022-12-17T23:55:41Z DEBUG ipaUniqueID 2022-12-17T23:55:41Z DEBUG ipauuidenforce: 2022-12-17T23:55:41Z DEBUG TRUE 2022-12-17T23:55:41Z DEBUG ipauuidfilter: 2022-12-17T23:55:41Z DEBUG (|(objectclass=ipaObject)(objectclass=ipaAssociation)) 2022-12-17T23:55:41Z DEBUG ipauuidmagicregen: 2022-12-17T23:55:41Z DEBUG autogenerate 2022-12-17T23:55:41Z DEBUG ipauuidscope: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG ipaUuidExcludeSubtree: 2022-12-17T23:55:41Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG [(2, 'ipaUuidExcludeSubtree', ['cn=provisioning,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(2, 'ipaUuidExcludeSubtree', [b'cn=provisioning,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-syncrepl.update 0.078 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/20-user_private_groups.update' 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG mepTemplateEntry 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG UPG Template 2022-12-17T23:55:41Z DEBUG mepRDNAttr: 2022-12-17T23:55:41Z DEBUG cn 2022-12-17T23:55:41Z DEBUG mepStaticAttr: 2022-12-17T23:55:41Z DEBUG objectclass: posixgroup 2022-12-17T23:55:41Z DEBUG objectclass: ipaobject 2022-12-17T23:55:41Z DEBUG ipaUniqueId: autogenerate 2022-12-17T23:55:41Z DEBUG mepMappedAttr: 2022-12-17T23:55:41Z DEBUG cn: $uid 2022-12-17T23:55:41Z DEBUG gidNumber: $uidNumber 2022-12-17T23:55:41Z DEBUG description: User private group for $uid 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG mepTemplateEntry 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG UPG Template 2022-12-17T23:55:41Z DEBUG mepRDNAttr: 2022-12-17T23:55:41Z DEBUG cn 2022-12-17T23:55:41Z DEBUG mepStaticAttr: 2022-12-17T23:55:41Z DEBUG objectclass: posixgroup 2022-12-17T23:55:41Z DEBUG objectclass: ipaobject 2022-12-17T23:55:41Z DEBUG ipaUniqueId: autogenerate 2022-12-17T23:55:41Z DEBUG mepMappedAttr: 2022-12-17T23:55:41Z DEBUG cn: $uid 2022-12-17T23:55:41Z DEBUG gidNumber: $uidNumber 2022-12-17T23:55:41Z DEBUG description: User private group for $uid 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG UPG Definition 2022-12-17T23:55:41Z DEBUG originScope: 2022-12-17T23:55:41Z DEBUG cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG originFilter: 2022-12-17T23:55:41Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2022-12-17T23:55:41Z DEBUG managedBase: 2022-12-17T23:55:41Z DEBUG cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG managedTemplate: 2022-12-17T23:55:41Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG UPG Definition 2022-12-17T23:55:41Z DEBUG originScope: 2022-12-17T23:55:41Z DEBUG cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG originFilter: 2022-12-17T23:55:41Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2022-12-17T23:55:41Z DEBUG managedBase: 2022-12-17T23:55:41Z DEBUG cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG managedTemplate: 2022-12-17T23:55:41Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG UPG Definition 2022-12-17T23:55:41Z DEBUG originScope: 2022-12-17T23:55:41Z DEBUG cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG originFilter: 2022-12-17T23:55:41Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2022-12-17T23:55:41Z DEBUG managedBase: 2022-12-17T23:55:41Z DEBUG cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG managedTemplate: 2022-12-17T23:55:41Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG replace: objectclass=posixAccount not found, skipping 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG UPG Definition 2022-12-17T23:55:41Z DEBUG originScope: 2022-12-17T23:55:41Z DEBUG cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG originFilter: 2022-12-17T23:55:41Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2022-12-17T23:55:41Z DEBUG managedBase: 2022-12-17T23:55:41Z DEBUG cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG managedTemplate: 2022-12-17T23:55:41Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-user_private_groups.update 0.010 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/20-uuid.update' 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG IPK11 Unique IDs 2022-12-17T23:55:41Z DEBUG ipauuidattr: 2022-12-17T23:55:41Z DEBUG ipk11UniqueID 2022-12-17T23:55:41Z DEBUG ipauuidenforce: 2022-12-17T23:55:41Z DEBUG FALSE 2022-12-17T23:55:41Z DEBUG ipauuidfilter: 2022-12-17T23:55:41Z DEBUG (objectclass=ipk11Object) 2022-12-17T23:55:41Z DEBUG ipauuidmagicregen: 2022-12-17T23:55:41Z DEBUG autogenerate 2022-12-17T23:55:41Z DEBUG ipauuidscope: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG IPK11 Unique IDs 2022-12-17T23:55:41Z DEBUG ipauuidattr: 2022-12-17T23:55:41Z DEBUG ipk11UniqueID 2022-12-17T23:55:41Z DEBUG ipauuidenforce: 2022-12-17T23:55:41Z DEBUG FALSE 2022-12-17T23:55:41Z DEBUG ipauuidfilter: 2022-12-17T23:55:41Z DEBUG (objectclass=ipk11Object) 2022-12-17T23:55:41Z DEBUG ipauuidmagicregen: 2022-12-17T23:55:41Z DEBUG autogenerate 2022-12-17T23:55:41Z DEBUG ipauuidscope: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-uuid.update 0.004 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/20-whoami.update' 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=whoami,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG whoami 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:41Z DEBUG database 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG whoami extended operation plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG whoami-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG whoami_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libwhoami-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG extendedop 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG 389 Project 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG 2.2.4 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG whoami 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:41Z DEBUG database 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG whoami extended operation plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG whoami-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG whoami_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libwhoami-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG extendedop 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG 389 Project 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG 2.2.4 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-whoami.update 0.005 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/21-ca_renewal_container.update' 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ca_renewal 2022-12-17T23:55:41Z DEBUG add: 'top' to objectClass, current value ['nsContainer', 'top'] 2022-12-17T23:55:41Z DEBUG add: updated value ['nsContainer', 'top'] 2022-12-17T23:55:41Z DEBUG add: 'nsContainer' to objectClass, current value ['nsContainer', 'top'] 2022-12-17T23:55:41Z DEBUG add: updated value ['top', 'nsContainer'] 2022-12-17T23:55:41Z DEBUG add: 'ca_renewal' to cn, current value ['ca_renewal'] 2022-12-17T23:55:41Z DEBUG add: updated value ['ca_renewal'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ca_renewal 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/21-ca_renewal_container.update 0.003 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/21-certstore_container.update' 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG certificates 2022-12-17T23:55:41Z DEBUG add: 'top' to objectClass, current value ['nsContainer', 'top'] 2022-12-17T23:55:41Z DEBUG add: updated value ['nsContainer', 'top'] 2022-12-17T23:55:41Z DEBUG add: 'nsContainer' to objectClass, current value ['nsContainer', 'top'] 2022-12-17T23:55:41Z DEBUG add: updated value ['top', 'nsContainer'] 2022-12-17T23:55:41Z DEBUG add: 'certificates' to cn, current value ['certificates'] 2022-12-17T23:55:41Z DEBUG add: updated value ['certificates'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG certificates 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/21-certstore_container.update 0.003 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/21-replicas_container.update' 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=replicas,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG replicas 2022-12-17T23:55:41Z DEBUG add: 'top' to objectClass, current value ['nsContainer', 'top'] 2022-12-17T23:55:41Z DEBUG add: updated value ['nsContainer', 'top'] 2022-12-17T23:55:41Z DEBUG add: 'nsContainer' to objectClass, current value ['nsContainer', 'top'] 2022-12-17T23:55:41Z DEBUG add: updated value ['top', 'nsContainer'] 2022-12-17T23:55:41Z DEBUG add: 'replicas' to cn, current value ['replicas'] 2022-12-17T23:55:41Z DEBUG add: updated value ['replicas'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG replicas 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/21-replicas_container.update 0.003 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/25-referint.update' 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG referential integrity postoperation 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:41Z DEBUG database 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG referential integrity plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG referint 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG referint_postop_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libreferint-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG betxnpostoperation 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG 389 Project 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG 2.2.4 2022-12-17T23:55:41Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:41Z DEBUG 40 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG referint-logfile: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/referint 2022-12-17T23:55:41Z DEBUG referint-membership-attr: 2022-12-17T23:55:41Z DEBUG member 2022-12-17T23:55:41Z DEBUG uniquemember 2022-12-17T23:55:41Z DEBUG owner 2022-12-17T23:55:41Z DEBUG seeAlso 2022-12-17T23:55:41Z DEBUG referint-update-delay: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-pluginentryscope: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-plugincontainerscope: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-pluginexcludeentryscope: 2022-12-17T23:55:41Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG add: 'manager' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager'] 2022-12-17T23:55:41Z DEBUG add: 'secretary' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary'] 2022-12-17T23:55:41Z DEBUG add: 'memberuser' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser'] 2022-12-17T23:55:41Z DEBUG add: 'memberhost' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost'] 2022-12-17T23:55:41Z DEBUG add: 'sourcehost' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost'] 2022-12-17T23:55:41Z DEBUG add: 'memberservice' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice'] 2022-12-17T23:55:41Z DEBUG add: 'managedby' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby'] 2022-12-17T23:55:41Z DEBUG add: 'memberallowcmd' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd'] 2022-12-17T23:55:41Z DEBUG add: 'memberdenycmd' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd'] 2022-12-17T23:55:41Z DEBUG add: 'ipasudorunas' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas'] 2022-12-17T23:55:41Z DEBUG add: 'ipasudorunasgroup' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup'] 2022-12-17T23:55:41Z DEBUG add: 'ipatokenradiusconfiglink' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink'] 2022-12-17T23:55:41Z DEBUG add: 'ipaassignedidview' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview'] 2022-12-17T23:55:41Z DEBUG add: 'ipaallowedtarget' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget'] 2022-12-17T23:55:41Z DEBUG add: 'ipamemberca' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca'] 2022-12-17T23:55:41Z DEBUG add: 'ipamembercertprofile' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile'] 2022-12-17T23:55:41Z DEBUG add: 'ipalocation' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation'] 2022-12-17T23:55:41Z DEBUG add: 'membermanager' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager'] 2022-12-17T23:55:41Z DEBUG add: 'ipaowner' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager', 'ipaowner'] 2022-12-17T23:55:41Z DEBUG add: 'ipaidpconfiglink' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager', 'ipaowner'] 2022-12-17T23:55:41Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager', 'ipaowner', 'ipaidpconfiglink'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG referential integrity postoperation 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:41Z DEBUG database 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG referential integrity plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG referint 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG referint_postop_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libreferint-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG betxnpostoperation 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG 389 Project 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG 2.2.4 2022-12-17T23:55:41Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:41Z DEBUG 40 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG referint-logfile: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/referint 2022-12-17T23:55:41Z DEBUG referint-membership-attr: 2022-12-17T23:55:41Z DEBUG member 2022-12-17T23:55:41Z DEBUG uniquemember 2022-12-17T23:55:41Z DEBUG owner 2022-12-17T23:55:41Z DEBUG seeAlso 2022-12-17T23:55:41Z DEBUG manager 2022-12-17T23:55:41Z DEBUG secretary 2022-12-17T23:55:41Z DEBUG memberuser 2022-12-17T23:55:41Z DEBUG memberhost 2022-12-17T23:55:41Z DEBUG sourcehost 2022-12-17T23:55:41Z DEBUG memberservice 2022-12-17T23:55:41Z DEBUG managedby 2022-12-17T23:55:41Z DEBUG memberallowcmd 2022-12-17T23:55:41Z DEBUG memberdenycmd 2022-12-17T23:55:41Z DEBUG ipasudorunas 2022-12-17T23:55:41Z DEBUG ipasudorunasgroup 2022-12-17T23:55:41Z DEBUG ipatokenradiusconfiglink 2022-12-17T23:55:41Z DEBUG ipaassignedidview 2022-12-17T23:55:41Z DEBUG ipaallowedtarget 2022-12-17T23:55:41Z DEBUG ipamemberca 2022-12-17T23:55:41Z DEBUG ipamembercertprofile 2022-12-17T23:55:41Z DEBUG ipalocation 2022-12-17T23:55:41Z DEBUG membermanager 2022-12-17T23:55:41Z DEBUG ipaowner 2022-12-17T23:55:41Z DEBUG ipaidpconfiglink 2022-12-17T23:55:41Z DEBUG referint-update-delay: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-pluginentryscope: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-plugincontainerscope: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-pluginexcludeentryscope: 2022-12-17T23:55:41Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG [(0, 'referint-membership-attr', ['manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager', 'ipaowner', 'ipaidpconfiglink'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(0, 'referint-membership-attr', [b'manager', b'secretary', b'memberuser', b'memberhost', b'sourcehost', b'memberservice', b'managedby', b'memberallowcmd', b'memberdenycmd', b'ipasudorunas', b'ipasudorunasgroup', b'ipatokenradiusconfiglink', b'ipaassignedidview', b'ipaallowedtarget', b'ipamemberca', b'ipamembercertprofile', b'ipalocation', b'membermanager', b'ipaowner', b'ipaidpconfiglink'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/25-referint.update 0.022 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/30-ipservices.update' 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=ipservices,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=ipservices,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ipservices 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=ipservices,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ipservices 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/30-ipservices.update 0.003 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/30-provisioning.update' 2022-12-17T23:55:41Z DEBUG New entry: cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectclass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG provisioning 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectclass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG provisioning 2022-12-17T23:55:41Z DEBUG New entry: cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectclass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG accounts 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectclass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG accounts 2022-12-17T23:55:41Z DEBUG New entry: cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectclass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG staged users 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectclass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG staged users 2022-12-17T23:55:41Z DEBUG New entry: cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectclass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG deleted users 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectclass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG deleted users 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG staged users 2022-12-17T23:55:41Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value [] 2022-12-17T23:55:41Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:41Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value [] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG staged users 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG [(2, 'aci', ['(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG deleted users 2022-12-17T23:55:41Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value [] 2022-12-17T23:55:41Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:41Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value [] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG add: '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)' to aci, current value ['(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG deleted users 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";) 2022-12-17T23:55:41Z DEBUG [(2, 'aci', ['(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', b'(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG New entry: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cosSuperDefinition 2022-12-17T23:55:41Z DEBUG cosPointerDefinition 2022-12-17T23:55:41Z DEBUG ldapSubEntry 2022-12-17T23:55:41Z DEBUG costemplatedn: 2022-12-17T23:55:41Z DEBUG cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG cosAttribute: 2022-12-17T23:55:41Z DEBUG nsaccountlock operational 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG provisioning accounts lock 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cosSuperDefinition 2022-12-17T23:55:41Z DEBUG cosPointerDefinition 2022-12-17T23:55:41Z DEBUG ldapSubEntry 2022-12-17T23:55:41Z DEBUG costemplatedn: 2022-12-17T23:55:41Z DEBUG cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG cosAttribute: 2022-12-17T23:55:41Z DEBUG nsaccountlock operational 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG provisioning accounts lock 2022-12-17T23:55:41Z DEBUG New entry: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG cosTemplate 2022-12-17T23:55:41Z DEBUG cosPriority: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Inactivation cos template 2022-12-17T23:55:41Z DEBUG nsAccountLock: 2022-12-17T23:55:41Z DEBUG true 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG cosTemplate 2022-12-17T23:55:41Z DEBUG cosPriority: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Inactivation cos template 2022-12-17T23:55:41Z DEBUG nsAccountLock: 2022-12-17T23:55:41Z DEBUG true 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/30-provisioning.update 0.037 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/30-s4u2proxy.update' 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG s4u2proxy 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG s4u2proxy 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG ipaKrb5DelegationACL 2022-12-17T23:55:41Z DEBUG groupOfPrincipals 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ipa-http-delegation 2022-12-17T23:55:41Z DEBUG memberPrincipal: 2022-12-17T23:55:41Z DEBUG HTTP/master.redacted_domain.com@REDACTED_DOMAIN.COM 2022-12-17T23:55:41Z DEBUG ipaAllowedTarget: 2022-12-17T23:55:41Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG ipaKrb5DelegationACL 2022-12-17T23:55:41Z DEBUG groupOfPrincipals 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ipa-http-delegation 2022-12-17T23:55:41Z DEBUG memberPrincipal: 2022-12-17T23:55:41Z DEBUG HTTP/master.redacted_domain.com@REDACTED_DOMAIN.COM 2022-12-17T23:55:41Z DEBUG ipaAllowedTarget: 2022-12-17T23:55:41Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG groupOfPrincipals 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ipa-ldap-delegation-targets 2022-12-17T23:55:41Z DEBUG memberPrincipal: 2022-12-17T23:55:41Z DEBUG ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG groupOfPrincipals 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ipa-ldap-delegation-targets 2022-12-17T23:55:41Z DEBUG memberPrincipal: 2022-12-17T23:55:41Z DEBUG ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG ipaKrb5DelegationACL 2022-12-17T23:55:41Z DEBUG groupOfPrincipals 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ipa-http-delegation 2022-12-17T23:55:41Z DEBUG memberPrincipal: 2022-12-17T23:55:41Z DEBUG HTTP/master.redacted_domain.com@REDACTED_DOMAIN.COM 2022-12-17T23:55:41Z DEBUG ipaAllowedTarget: 2022-12-17T23:55:41Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG add: 'HTTP/master.redacted_domain.com@REDACTED_DOMAIN.COM' to memberPrincipal, current value ['HTTP/master.redacted_domain.com@REDACTED_DOMAIN.COM'] 2022-12-17T23:55:41Z DEBUG add: updated value ['HTTP/master.redacted_domain.com@REDACTED_DOMAIN.COM'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG ipaKrb5DelegationACL 2022-12-17T23:55:41Z DEBUG groupOfPrincipals 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ipa-http-delegation 2022-12-17T23:55:41Z DEBUG memberPrincipal: 2022-12-17T23:55:41Z DEBUG HTTP/master.redacted_domain.com@REDACTED_DOMAIN.COM 2022-12-17T23:55:41Z DEBUG ipaAllowedTarget: 2022-12-17T23:55:41Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG groupOfPrincipals 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ipa-ldap-delegation-targets 2022-12-17T23:55:41Z DEBUG memberPrincipal: 2022-12-17T23:55:41Z DEBUG ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM 2022-12-17T23:55:41Z DEBUG add: 'ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM' to memberPrincipal, current value ['ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM'] 2022-12-17T23:55:41Z DEBUG add: updated value ['ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG groupOfPrincipals 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ipa-ldap-delegation-targets 2022-12-17T23:55:41Z DEBUG memberPrincipal: 2022-12-17T23:55:41Z DEBUG ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/30-s4u2proxy.update 0.013 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/37-locations.update' 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=locations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=locations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG locations 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=locations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG locations 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/37-locations.update 0.002 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/40-automember.update' 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG automemberprocessmodifyops: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Auto Membership Plugin 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:41Z DEBUG database 2022-12-17T23:55:41Z DEBUG nsslapd-pluginConfigArea: 2022-12-17T23:55:41Z DEBUG cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG Auto Membership plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG Auto Membership 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG automember_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libautomember-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG betxnpreoperation 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG 389 Project 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG 2.2.4 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG addifnew: 'cn=automember,cn=etc,dc=redacted_domain,dc=com' to nsslapd-pluginConfigArea, current value ['cn=automember,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG automemberprocessmodifyops: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Auto Membership Plugin 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:41Z DEBUG database 2022-12-17T23:55:41Z DEBUG nsslapd-pluginConfigArea: 2022-12-17T23:55:41Z DEBUG cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:41Z DEBUG Auto Membership plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:41Z DEBUG Auto Membership 2022-12-17T23:55:41Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:41Z DEBUG automember_init 2022-12-17T23:55:41Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:41Z DEBUG libautomember-plugin 2022-12-17T23:55:41Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:41Z DEBUG betxnpreoperation 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:41Z DEBUG 389 Project 2022-12-17T23:55:41Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:41Z DEBUG 2.2.4 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsSlapdPlugin 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG automember 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG automember 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=Hostgroup,cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Hostgroup,cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG autoMemberDefinition 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Hostgroup 2022-12-17T23:55:41Z DEBUG autoMemberScope: 2022-12-17T23:55:41Z DEBUG cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG autoMemberFilter: 2022-12-17T23:55:41Z DEBUG objectclass=ipaHost 2022-12-17T23:55:41Z DEBUG autoMemberGroupingAttr: 2022-12-17T23:55:41Z DEBUG member:dn 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Hostgroup,cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG autoMemberDefinition 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Hostgroup 2022-12-17T23:55:41Z DEBUG autoMemberScope: 2022-12-17T23:55:41Z DEBUG cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG autoMemberFilter: 2022-12-17T23:55:41Z DEBUG objectclass=ipaHost 2022-12-17T23:55:41Z DEBUG autoMemberGroupingAttr: 2022-12-17T23:55:41Z DEBUG member:dn 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=Group,cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Group,cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG autoMemberDefinition 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Group 2022-12-17T23:55:41Z DEBUG autoMemberScope: 2022-12-17T23:55:41Z DEBUG cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG autoMemberFilter: 2022-12-17T23:55:41Z DEBUG objectclass=posixAccount 2022-12-17T23:55:41Z DEBUG autoMemberGroupingAttr: 2022-12-17T23:55:41Z DEBUG member:dn 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Group,cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG autoMemberDefinition 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Group 2022-12-17T23:55:41Z DEBUG autoMemberScope: 2022-12-17T23:55:41Z DEBUG cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG autoMemberFilter: 2022-12-17T23:55:41Z DEBUG objectclass=posixAccount 2022-12-17T23:55:41Z DEBUG autoMemberGroupingAttr: 2022-12-17T23:55:41Z DEBUG member:dn 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-automember.update 0.014 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/40-certprofile.update' 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ca 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ca 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=certprofiles,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=certprofiles,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG certprofiles 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=certprofiles,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG certprofiles 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-certprofile.update 0.005 sec 2022-12-17T23:55:41Z DEBUG Parsing update file '/usr/share/ipa/updates/40-delegation.update' 2022-12-17T23:55:41Z DEBUG New entry: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Write IPA Configuration 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Write IPA Configuration 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Write IPA Configuration 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Write IPA Configuration 2022-12-17T23:55:41Z DEBUG New entry: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Write IPA Configuration 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Write IPA Configuration 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG domain 2022-12-17T23:55:41Z DEBUG pilotObject 2022-12-17T23:55:41Z DEBUG domainRelatedObject 2022-12-17T23:55:41Z DEBUG nisDomainObject 2022-12-17T23:55:41Z DEBUG dc: 2022-12-17T23:55:41Z DEBUG redacted_domain 2022-12-17T23:55:41Z DEBUG info: 2022-12-17T23:55:41Z DEBUG IPA V2.0 2022-12-17T23:55:41Z DEBUG associatedDomain: 2022-12-17T23:55:41Z DEBUG redacted_domain.com 2022-12-17T23:55:41Z DEBUG nisDomain: 2022-12-17T23:55:41Z DEBUG redacted_domain.com 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:41Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG add: '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG domain 2022-12-17T23:55:41Z DEBUG pilotObject 2022-12-17T23:55:41Z DEBUG domainRelatedObject 2022-12-17T23:55:41Z DEBUG nisDomainObject 2022-12-17T23:55:41Z DEBUG dc: 2022-12-17T23:55:41Z DEBUG redacted_domain 2022-12-17T23:55:41Z DEBUG info: 2022-12-17T23:55:41Z DEBUG IPA V2.0 2022-12-17T23:55:41Z DEBUG associatedDomain: 2022-12-17T23:55:41Z DEBUG redacted_domain.com 2022-12-17T23:55:41Z DEBUG nisDomain: 2022-12-17T23:55:41Z DEBUG redacted_domain.com 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:41Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG [(0, 'aci', ['(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG New entry: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG HBAC Administrator 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG HBAC Administrator 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG HBAC Administrator 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG HBAC Administrator 2022-12-17T23:55:41Z DEBUG New entry: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Sudo Administrator 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Sudo Administrator 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Sudo Administrator 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Sudo Administrator 2022-12-17T23:55:41Z DEBUG New entry: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Password Policy Administrator 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Password Policy Administrator 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Password Policy Administrator 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Password Policy Administrator 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=Host Enrollment,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Host Enrollment 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Host Enrollment 2022-12-17T23:55:41Z DEBUG add: 'cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:41Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Host Enrollment 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Host Enrollment 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG [(2, 'member', ['cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(2, 'member', [b'cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG domain 2022-12-17T23:55:41Z DEBUG pilotObject 2022-12-17T23:55:41Z DEBUG domainRelatedObject 2022-12-17T23:55:41Z DEBUG nisDomainObject 2022-12-17T23:55:41Z DEBUG dc: 2022-12-17T23:55:41Z DEBUG redacted_domain 2022-12-17T23:55:41Z DEBUG info: 2022-12-17T23:55:41Z DEBUG IPA V2.0 2022-12-17T23:55:41Z DEBUG associatedDomain: 2022-12-17T23:55:41Z DEBUG redacted_domain.com 2022-12-17T23:55:41Z DEBUG nisDomain: 2022-12-17T23:55:41Z DEBUG redacted_domain.com 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:41Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Add DNS entries";allow (add) groupdn = "ldap:///cn=add dns entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Add DNS entries";allow (add) groupdn = "ldap:///cn=add dns entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:41Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Remove DNS entries";allow (delete) groupdn = "ldap:///cn=remove dns entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Remove DNS entries";allow (delete) groupdn = "ldap:///cn=remove dns entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:41Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Update DNS entries";allow (write) groupdn = "ldap:///cn=update dns entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Update DNS entries";allow (write) groupdn = "ldap:///cn=update dns entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG domain 2022-12-17T23:55:41Z DEBUG pilotObject 2022-12-17T23:55:41Z DEBUG domainRelatedObject 2022-12-17T23:55:41Z DEBUG nisDomainObject 2022-12-17T23:55:41Z DEBUG dc: 2022-12-17T23:55:41Z DEBUG redacted_domain 2022-12-17T23:55:41Z DEBUG info: 2022-12-17T23:55:41Z DEBUG IPA V2.0 2022-12-17T23:55:41Z DEBUG associatedDomain: 2022-12-17T23:55:41Z DEBUG redacted_domain.com 2022-12-17T23:55:41Z DEBUG nisDomain: 2022-12-17T23:55:41Z DEBUG redacted_domain.com 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:41Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG [] 2022-12-17T23:55:41Z DEBUG Updated 0 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG New entry: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG SELinux User Map Administrators 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG SELinux User Map Administrators 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG SELinux User Map Administrators 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG SELinux User Map Administrators 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ipa 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) userdn = "ldap:///fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) userdn = "ldap:///fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:41Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) userdn = "ldap:///fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) userdn = "ldap:///fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:41Z DEBUG add: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG add: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ipa 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)', b'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Retrieve Certificates from the CA 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG add: 'cn=Host Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com' to member, current value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG add: updated value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com', 'cn=Host Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Retrieve Certificates from the CA 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG [(0, 'member', ['cn=Host Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(0, 'member', [b'cn=Host Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Revoke Certificate 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG add: 'cn=Host Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com' to member, current value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG add: updated value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com', 'cn=Host Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Revoke Certificate 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG [(0, 'member', ['cn=Host Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(0, 'member', [b'cn=Host Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ipa 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) userdn = "ldap:///fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) userdn = "ldap:///fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:41Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:41Z DEBUG add: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "cACertificate")(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "cACertificate")(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG ipa 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "cACertificate")(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "cACertificate")(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr = "cACertificate")(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG certificates 2022-12-17T23:55:41Z DEBUG remove: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) userdn = "ldap:///fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value [] 2022-12-17T23:55:41Z DEBUG remove: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) userdn = "ldap:///fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:41Z DEBUG add: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value [] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG certificates 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG [(2, 'aci', ['(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG New entry: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Automember Task Administrator 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Automember Task Administrator 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Automember Task Administrator 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Automember Task Administrator 2022-12-17T23:55:41Z DEBUG New entry: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Add Automember Rebuild Membership Task 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG ipapermissiontype: 2022-12-17T23:55:41Z DEBUG SYSTEM 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Add Automember Rebuild Membership Task 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG ipapermissiontype: 2022-12-17T23:55:41Z DEBUG SYSTEM 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG config 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG nsslapdConfig 2022-12-17T23:55:41Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:41Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-betype: 2022-12-17T23:55:41Z DEBUG ldbm database 2022-12-17T23:55:41Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:41Z DEBUG cn=schema 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-plugin: 2022-12-17T23:55:41Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:41Z DEBUG 16384 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-port: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-localuser: 2022-12-17T23:55:41Z DEBUG dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordInHistory: 2022-12-17T23:55:41Z DEBUG 6 2022-12-17T23:55:41Z DEBUG passwordUnlock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordGraceLimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordMustChange: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:41Z DEBUG 100000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordWarning: 2022-12-17T23:55:41Z DEBUG 86400 2022-12-17T23:55:41Z DEBUG nsslapd-readonly: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:41Z DEBUG 16 2022-12-17T23:55:41Z DEBUG passwordLockout: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-localhost: 2022-12-17T23:55:41Z DEBUG master.redacted_domain.com 2022-12-17T23:55:41Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:41Z DEBUG 10000 2022-12-17T23:55:41Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:41Z DEBUG 40 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordMinLength: 2022-12-17T23:55:41Z DEBUG 8 2022-12-17T23:55:41Z DEBUG passwordMinDigits: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinAlphas: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinUppers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinLowers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinSpecials: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMin8bit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinCategories: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordPalindrome: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictCheck: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictPath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordUserAttributes: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordBadWords: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordMaxSequence: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:41Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:41Z DEBUG replication-only 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG passwordMaxFailure: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:41Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-security: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordMaxAge: 2022-12-17T23:55:41Z DEBUG 8640000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:41Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:41Z DEBUG passwordChange: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securePort: 2022-12-17T23:55:41Z DEBUG 636 2022-12-17T23:55:41Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:41Z DEBUG 64 2022-12-17T23:55:41Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordExp: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG day 2022-12-17T23:55:41Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-nagle: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:41Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:41Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:41Z DEBUG uidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:41Z DEBUG gidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:41Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-counters: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG passwordMinAge: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:41Z DEBUG 209715200 2022-12-17T23:55:41Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:41Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:41Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:41Z DEBUG 524288 2022-12-17T23:55:41Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:41Z DEBUG 1024 2022-12-17T23:55:41Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:41Z DEBUG allowed 2022-12-17T23:55:41Z DEBUG nsslapd-config: 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:41Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:41Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:41Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:41Z DEBUG /tmp 2022-12-17T23:55:41Z DEBUG nsslapd-certdir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:41Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:41Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rundir: 2022-12-17T23:55:41Z DEBUG /run/dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:41Z DEBUG 300000 2022-12-17T23:55:41Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-localssf: 2022-12-17T23:55:41Z DEBUG 71 2022-12-17T23:55:41Z DEBUG nsslapd-minssf: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:41Z DEBUG next 2022-12-17T23:55:41Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:41Z DEBUG warn 2022-12-17T23:55:41Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:41Z DEBUG 60 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:41Z DEBUG 20971520 2022-12-17T23:55:41Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:41Z DEBUG nolog 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:41Z DEBUG 128 2022-12-17T23:55:41Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:41Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:41Z DEBUG dirsrv-log 2022-12-17T23:55:41Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:41Z DEBUG process-safe 2022-12-17T23:55:41Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:41Z DEBUG 30 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:41Z DEBUG 300 2022-12-17T23:55:41Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordStorageScheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG passwordAdminDN: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:41Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:41Z DEBUG remove: '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2022-12-17T23:55:41Z DEBUG remove: '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:41Z DEBUG add: '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG config 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG nsslapdConfig 2022-12-17T23:55:41Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:41Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-betype: 2022-12-17T23:55:41Z DEBUG ldbm database 2022-12-17T23:55:41Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:41Z DEBUG cn=schema 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-plugin: 2022-12-17T23:55:41Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:41Z DEBUG 16384 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-port: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-localuser: 2022-12-17T23:55:41Z DEBUG dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordInHistory: 2022-12-17T23:55:41Z DEBUG 6 2022-12-17T23:55:41Z DEBUG passwordUnlock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordGraceLimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordMustChange: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:41Z DEBUG 100000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordWarning: 2022-12-17T23:55:41Z DEBUG 86400 2022-12-17T23:55:41Z DEBUG nsslapd-readonly: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:41Z DEBUG 16 2022-12-17T23:55:41Z DEBUG passwordLockout: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-localhost: 2022-12-17T23:55:41Z DEBUG master.redacted_domain.com 2022-12-17T23:55:41Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:41Z DEBUG 10000 2022-12-17T23:55:41Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:41Z DEBUG 40 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordMinLength: 2022-12-17T23:55:41Z DEBUG 8 2022-12-17T23:55:41Z DEBUG passwordMinDigits: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinAlphas: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinUppers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinLowers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinSpecials: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMin8bit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinCategories: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordPalindrome: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictCheck: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictPath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordUserAttributes: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordBadWords: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordMaxSequence: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:41Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:41Z DEBUG replication-only 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG passwordMaxFailure: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:41Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-security: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordMaxAge: 2022-12-17T23:55:41Z DEBUG 8640000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:41Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:41Z DEBUG passwordChange: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securePort: 2022-12-17T23:55:41Z DEBUG 636 2022-12-17T23:55:41Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:41Z DEBUG 64 2022-12-17T23:55:41Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordExp: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG day 2022-12-17T23:55:41Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-nagle: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:41Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:41Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:41Z DEBUG uidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:41Z DEBUG gidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:41Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-counters: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG passwordMinAge: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:41Z DEBUG 209715200 2022-12-17T23:55:41Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:41Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:41Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:41Z DEBUG 524288 2022-12-17T23:55:41Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:41Z DEBUG 1024 2022-12-17T23:55:41Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:41Z DEBUG allowed 2022-12-17T23:55:41Z DEBUG nsslapd-config: 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:41Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:41Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:41Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:41Z DEBUG /tmp 2022-12-17T23:55:41Z DEBUG nsslapd-certdir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:41Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:41Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rundir: 2022-12-17T23:55:41Z DEBUG /run/dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:41Z DEBUG 300000 2022-12-17T23:55:41Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-localssf: 2022-12-17T23:55:41Z DEBUG 71 2022-12-17T23:55:41Z DEBUG nsslapd-minssf: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:41Z DEBUG next 2022-12-17T23:55:41Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:41Z DEBUG warn 2022-12-17T23:55:41Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:41Z DEBUG 60 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:41Z DEBUG 20971520 2022-12-17T23:55:41Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:41Z DEBUG nolog 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:41Z DEBUG 128 2022-12-17T23:55:41Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:41Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:41Z DEBUG dirsrv-log 2022-12-17T23:55:41Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:41Z DEBUG process-safe 2022-12-17T23:55:41Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:41Z DEBUG 30 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:41Z DEBUG 300 2022-12-17T23:55:41Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordStorageScheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG passwordAdminDN: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:41Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG New entry: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG retrieve certificate 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG retrieve certificate 2022-12-17T23:55:41Z DEBUG New entry: cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG request certificate 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG request certificate 2022-12-17T23:55:41Z DEBUG New entry: cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG request certificate different host 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG request certificate different host 2022-12-17T23:55:41Z DEBUG New entry: cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG certificate status 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG certificate status 2022-12-17T23:55:41Z DEBUG New entry: cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG revoke certificate 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG revoke certificate 2022-12-17T23:55:41Z DEBUG New entry: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG certificate remove hold 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG certificate remove hold 2022-12-17T23:55:41Z DEBUG New entry: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG request certificate ignore caacl 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG request certificate ignore caacl 2022-12-17T23:55:41Z DEBUG New entry: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Request Certificate ignoring CA ACLs 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Request Certificate ignoring CA ACLs 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG domain 2022-12-17T23:55:41Z DEBUG pilotObject 2022-12-17T23:55:41Z DEBUG domainRelatedObject 2022-12-17T23:55:41Z DEBUG nisDomainObject 2022-12-17T23:55:41Z DEBUG dc: 2022-12-17T23:55:41Z DEBUG redacted_domain 2022-12-17T23:55:41Z DEBUG info: 2022-12-17T23:55:41Z DEBUG IPA V2.0 2022-12-17T23:55:41Z DEBUG associatedDomain: 2022-12-17T23:55:41Z DEBUG redacted_domain.com 2022-12-17T23:55:41Z DEBUG nisDomain: 2022-12-17T23:55:41Z DEBUG redacted_domain.com 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:41Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG add: '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG domain 2022-12-17T23:55:41Z DEBUG pilotObject 2022-12-17T23:55:41Z DEBUG domainRelatedObject 2022-12-17T23:55:41Z DEBUG nisDomainObject 2022-12-17T23:55:41Z DEBUG dc: 2022-12-17T23:55:41Z DEBUG redacted_domain 2022-12-17T23:55:41Z DEBUG info: 2022-12-17T23:55:41Z DEBUG IPA V2.0 2022-12-17T23:55:41Z DEBUG associatedDomain: 2022-12-17T23:55:41Z DEBUG redacted_domain.com 2022-12-17T23:55:41Z DEBUG nisDomain: 2022-12-17T23:55:41Z DEBUG redacted_domain.com 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:41Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:41Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:41Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG [(0, 'aci', ['(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG New entry: cn=RBAC Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=RBAC Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG RBAC Readers 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Read roles, privileges, permissions and ACIs 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=RBAC Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG RBAC Readers 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Read roles, privileges, permissions and ACIs 2022-12-17T23:55:41Z DEBUG New entry: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Password Policy Readers 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Read password policies 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Password Policy Readers 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Read password policies 2022-12-17T23:55:41Z DEBUG New entry: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Kerberos Ticket Policy Readers 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Read global and per-user Kerberos ticket policy 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Kerberos Ticket Policy Readers 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Read global and per-user Kerberos ticket policy 2022-12-17T23:55:41Z DEBUG New entry: cn=Automember Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Automember Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Automember Readers 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Read Automember definitions 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Automember Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Automember Readers 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Read Automember definitions 2022-12-17T23:55:41Z DEBUG New entry: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG IPA Masters Readers 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Read list of IPA masters 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG IPA Masters Readers 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG Read list of IPA masters 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG masters 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) userdn = "ldap:///fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) userdn = "ldap:///fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:41Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) userdn = "ldap:///fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) userdn = "ldap:///fqdn=master.redacted_domain.com,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:41Z DEBUG add: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG add: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nsContainer 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG masters 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG [(0, 'aci', ['(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)', b'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG New entry: cn=PassSync Service,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=PassSync Service,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG PassSync Service 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG PassSync Service 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=PassSync Service,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG nestedgroup 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG PassSync Service 2022-12-17T23:55:41Z DEBUG description: 2022-12-17T23:55:41Z DEBUG PassSync Service 2022-12-17T23:55:41Z DEBUG New entry: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Read PassSync Managers Configuration 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG ipapermissiontype: 2022-12-17T23:55:41Z DEBUG SYSTEM 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Read PassSync Managers Configuration 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG ipapermissiontype: 2022-12-17T23:55:41Z DEBUG SYSTEM 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG config 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG nsslapdConfig 2022-12-17T23:55:41Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:41Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-betype: 2022-12-17T23:55:41Z DEBUG ldbm database 2022-12-17T23:55:41Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:41Z DEBUG cn=schema 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-plugin: 2022-12-17T23:55:41Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:41Z DEBUG 16384 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-port: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-localuser: 2022-12-17T23:55:41Z DEBUG dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordInHistory: 2022-12-17T23:55:41Z DEBUG 6 2022-12-17T23:55:41Z DEBUG passwordUnlock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordGraceLimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordMustChange: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:41Z DEBUG 100000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordWarning: 2022-12-17T23:55:41Z DEBUG 86400 2022-12-17T23:55:41Z DEBUG nsslapd-readonly: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:41Z DEBUG 16 2022-12-17T23:55:41Z DEBUG passwordLockout: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-localhost: 2022-12-17T23:55:41Z DEBUG master.redacted_domain.com 2022-12-17T23:55:41Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:41Z DEBUG 10000 2022-12-17T23:55:41Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:41Z DEBUG 40 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordMinLength: 2022-12-17T23:55:41Z DEBUG 8 2022-12-17T23:55:41Z DEBUG passwordMinDigits: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinAlphas: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinUppers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinLowers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinSpecials: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMin8bit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinCategories: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordPalindrome: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictCheck: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictPath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordUserAttributes: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordBadWords: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordMaxSequence: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:41Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:41Z DEBUG replication-only 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG passwordMaxFailure: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:41Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-security: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordMaxAge: 2022-12-17T23:55:41Z DEBUG 8640000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:41Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:41Z DEBUG passwordChange: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securePort: 2022-12-17T23:55:41Z DEBUG 636 2022-12-17T23:55:41Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:41Z DEBUG 64 2022-12-17T23:55:41Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordExp: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG day 2022-12-17T23:55:41Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-nagle: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:41Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:41Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:41Z DEBUG uidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:41Z DEBUG gidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:41Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-counters: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG passwordMinAge: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:41Z DEBUG 209715200 2022-12-17T23:55:41Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:41Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:41Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:41Z DEBUG 524288 2022-12-17T23:55:41Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:41Z DEBUG 1024 2022-12-17T23:55:41Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:41Z DEBUG allowed 2022-12-17T23:55:41Z DEBUG nsslapd-config: 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:41Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:41Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:41Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:41Z DEBUG /tmp 2022-12-17T23:55:41Z DEBUG nsslapd-certdir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:41Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:41Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rundir: 2022-12-17T23:55:41Z DEBUG /run/dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:41Z DEBUG 300000 2022-12-17T23:55:41Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-localssf: 2022-12-17T23:55:41Z DEBUG 71 2022-12-17T23:55:41Z DEBUG nsslapd-minssf: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:41Z DEBUG next 2022-12-17T23:55:41Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:41Z DEBUG warn 2022-12-17T23:55:41Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:41Z DEBUG 60 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:41Z DEBUG 20971520 2022-12-17T23:55:41Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:41Z DEBUG nolog 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:41Z DEBUG 128 2022-12-17T23:55:41Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:41Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:41Z DEBUG dirsrv-log 2022-12-17T23:55:41Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:41Z DEBUG process-safe 2022-12-17T23:55:41Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:41Z DEBUG 30 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:41Z DEBUG 300 2022-12-17T23:55:41Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordStorageScheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG passwordAdminDN: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:41Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG add: '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG config 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG nsslapdConfig 2022-12-17T23:55:41Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:41Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-betype: 2022-12-17T23:55:41Z DEBUG ldbm database 2022-12-17T23:55:41Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:41Z DEBUG cn=schema 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-plugin: 2022-12-17T23:55:41Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:41Z DEBUG 16384 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-port: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-localuser: 2022-12-17T23:55:41Z DEBUG dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordInHistory: 2022-12-17T23:55:41Z DEBUG 6 2022-12-17T23:55:41Z DEBUG passwordUnlock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordGraceLimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordMustChange: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:41Z DEBUG 100000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordWarning: 2022-12-17T23:55:41Z DEBUG 86400 2022-12-17T23:55:41Z DEBUG nsslapd-readonly: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:41Z DEBUG 16 2022-12-17T23:55:41Z DEBUG passwordLockout: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-localhost: 2022-12-17T23:55:41Z DEBUG master.redacted_domain.com 2022-12-17T23:55:41Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:41Z DEBUG 10000 2022-12-17T23:55:41Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:41Z DEBUG 40 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordMinLength: 2022-12-17T23:55:41Z DEBUG 8 2022-12-17T23:55:41Z DEBUG passwordMinDigits: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinAlphas: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinUppers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinLowers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinSpecials: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMin8bit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinCategories: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordPalindrome: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictCheck: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictPath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordUserAttributes: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordBadWords: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordMaxSequence: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:41Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:41Z DEBUG replication-only 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG passwordMaxFailure: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:41Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-security: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordMaxAge: 2022-12-17T23:55:41Z DEBUG 8640000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:41Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:41Z DEBUG passwordChange: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securePort: 2022-12-17T23:55:41Z DEBUG 636 2022-12-17T23:55:41Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:41Z DEBUG 64 2022-12-17T23:55:41Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordExp: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG day 2022-12-17T23:55:41Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-nagle: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:41Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:41Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:41Z DEBUG uidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:41Z DEBUG gidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:41Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-counters: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG passwordMinAge: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:41Z DEBUG 209715200 2022-12-17T23:55:41Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:41Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:41Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:41Z DEBUG 524288 2022-12-17T23:55:41Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:41Z DEBUG 1024 2022-12-17T23:55:41Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:41Z DEBUG allowed 2022-12-17T23:55:41Z DEBUG nsslapd-config: 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:41Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:41Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:41Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:41Z DEBUG /tmp 2022-12-17T23:55:41Z DEBUG nsslapd-certdir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:41Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:41Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rundir: 2022-12-17T23:55:41Z DEBUG /run/dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:41Z DEBUG 300000 2022-12-17T23:55:41Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-localssf: 2022-12-17T23:55:41Z DEBUG 71 2022-12-17T23:55:41Z DEBUG nsslapd-minssf: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:41Z DEBUG next 2022-12-17T23:55:41Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:41Z DEBUG warn 2022-12-17T23:55:41Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:41Z DEBUG 60 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:41Z DEBUG 20971520 2022-12-17T23:55:41Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:41Z DEBUG nolog 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:41Z DEBUG 128 2022-12-17T23:55:41Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:41Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:41Z DEBUG dirsrv-log 2022-12-17T23:55:41Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:41Z DEBUG process-safe 2022-12-17T23:55:41Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:41Z DEBUG 30 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:41Z DEBUG 300 2022-12-17T23:55:41Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordStorageScheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG passwordAdminDN: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:41Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG [(0, 'aci', ['(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG New entry: cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Read Replication Changelog Configuration 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG ipapermissiontype: 2022-12-17T23:55:41Z DEBUG SYSTEM 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Read Replication Changelog Configuration 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG ipapermissiontype: 2022-12-17T23:55:41Z DEBUG SYSTEM 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG config 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG nsslapdConfig 2022-12-17T23:55:41Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:41Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-betype: 2022-12-17T23:55:41Z DEBUG ldbm database 2022-12-17T23:55:41Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:41Z DEBUG cn=schema 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-plugin: 2022-12-17T23:55:41Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:41Z DEBUG 16384 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-port: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-localuser: 2022-12-17T23:55:41Z DEBUG dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordInHistory: 2022-12-17T23:55:41Z DEBUG 6 2022-12-17T23:55:41Z DEBUG passwordUnlock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordGraceLimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordMustChange: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:41Z DEBUG 100000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordWarning: 2022-12-17T23:55:41Z DEBUG 86400 2022-12-17T23:55:41Z DEBUG nsslapd-readonly: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:41Z DEBUG 16 2022-12-17T23:55:41Z DEBUG passwordLockout: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-localhost: 2022-12-17T23:55:41Z DEBUG master.redacted_domain.com 2022-12-17T23:55:41Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:41Z DEBUG 10000 2022-12-17T23:55:41Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:41Z DEBUG 40 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordMinLength: 2022-12-17T23:55:41Z DEBUG 8 2022-12-17T23:55:41Z DEBUG passwordMinDigits: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinAlphas: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinUppers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinLowers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinSpecials: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMin8bit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinCategories: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordPalindrome: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictCheck: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictPath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordUserAttributes: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordBadWords: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordMaxSequence: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:41Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:41Z DEBUG replication-only 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG passwordMaxFailure: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:41Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-security: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordMaxAge: 2022-12-17T23:55:41Z DEBUG 8640000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:41Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:41Z DEBUG passwordChange: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securePort: 2022-12-17T23:55:41Z DEBUG 636 2022-12-17T23:55:41Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:41Z DEBUG 64 2022-12-17T23:55:41Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordExp: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG day 2022-12-17T23:55:41Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-nagle: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:41Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:41Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:41Z DEBUG uidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:41Z DEBUG gidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:41Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-counters: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG passwordMinAge: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:41Z DEBUG 209715200 2022-12-17T23:55:41Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:41Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:41Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:41Z DEBUG 524288 2022-12-17T23:55:41Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:41Z DEBUG 1024 2022-12-17T23:55:41Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:41Z DEBUG allowed 2022-12-17T23:55:41Z DEBUG nsslapd-config: 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:41Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:41Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:41Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:41Z DEBUG /tmp 2022-12-17T23:55:41Z DEBUG nsslapd-certdir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:41Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:41Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rundir: 2022-12-17T23:55:41Z DEBUG /run/dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:41Z DEBUG 300000 2022-12-17T23:55:41Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-localssf: 2022-12-17T23:55:41Z DEBUG 71 2022-12-17T23:55:41Z DEBUG nsslapd-minssf: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:41Z DEBUG next 2022-12-17T23:55:41Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:41Z DEBUG warn 2022-12-17T23:55:41Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:41Z DEBUG 60 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:41Z DEBUG 20971520 2022-12-17T23:55:41Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:41Z DEBUG nolog 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:41Z DEBUG 128 2022-12-17T23:55:41Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:41Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:41Z DEBUG dirsrv-log 2022-12-17T23:55:41Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:41Z DEBUG process-safe 2022-12-17T23:55:41Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:41Z DEBUG 30 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:41Z DEBUG 300 2022-12-17T23:55:41Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordStorageScheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG passwordAdminDN: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:41Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG add: '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG config 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG nsslapdConfig 2022-12-17T23:55:41Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:41Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-betype: 2022-12-17T23:55:41Z DEBUG ldbm database 2022-12-17T23:55:41Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:41Z DEBUG cn=schema 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-plugin: 2022-12-17T23:55:41Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:41Z DEBUG 16384 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-port: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-localuser: 2022-12-17T23:55:41Z DEBUG dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordInHistory: 2022-12-17T23:55:41Z DEBUG 6 2022-12-17T23:55:41Z DEBUG passwordUnlock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordGraceLimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordMustChange: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:41Z DEBUG 100000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordWarning: 2022-12-17T23:55:41Z DEBUG 86400 2022-12-17T23:55:41Z DEBUG nsslapd-readonly: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:41Z DEBUG 16 2022-12-17T23:55:41Z DEBUG passwordLockout: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-localhost: 2022-12-17T23:55:41Z DEBUG master.redacted_domain.com 2022-12-17T23:55:41Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:41Z DEBUG 10000 2022-12-17T23:55:41Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:41Z DEBUG 40 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordMinLength: 2022-12-17T23:55:41Z DEBUG 8 2022-12-17T23:55:41Z DEBUG passwordMinDigits: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinAlphas: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinUppers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinLowers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinSpecials: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMin8bit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinCategories: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordPalindrome: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictCheck: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictPath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordUserAttributes: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordBadWords: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordMaxSequence: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:41Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:41Z DEBUG replication-only 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG passwordMaxFailure: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:41Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-security: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordMaxAge: 2022-12-17T23:55:41Z DEBUG 8640000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:41Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:41Z DEBUG passwordChange: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securePort: 2022-12-17T23:55:41Z DEBUG 636 2022-12-17T23:55:41Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:41Z DEBUG 64 2022-12-17T23:55:41Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordExp: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG day 2022-12-17T23:55:41Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-nagle: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:41Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:41Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:41Z DEBUG uidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:41Z DEBUG gidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:41Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-counters: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG passwordMinAge: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:41Z DEBUG 209715200 2022-12-17T23:55:41Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:41Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:41Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:41Z DEBUG 524288 2022-12-17T23:55:41Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:41Z DEBUG 1024 2022-12-17T23:55:41Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:41Z DEBUG allowed 2022-12-17T23:55:41Z DEBUG nsslapd-config: 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:41Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:41Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:41Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:41Z DEBUG /tmp 2022-12-17T23:55:41Z DEBUG nsslapd-certdir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:41Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:41Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rundir: 2022-12-17T23:55:41Z DEBUG /run/dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:41Z DEBUG 300000 2022-12-17T23:55:41Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-localssf: 2022-12-17T23:55:41Z DEBUG 71 2022-12-17T23:55:41Z DEBUG nsslapd-minssf: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:41Z DEBUG next 2022-12-17T23:55:41Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:41Z DEBUG warn 2022-12-17T23:55:41Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:41Z DEBUG 60 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:41Z DEBUG 20971520 2022-12-17T23:55:41Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:41Z DEBUG nolog 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:41Z DEBUG 128 2022-12-17T23:55:41Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:41Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:41Z DEBUG dirsrv-log 2022-12-17T23:55:41Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:41Z DEBUG process-safe 2022-12-17T23:55:41Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:41Z DEBUG 30 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:41Z DEBUG 300 2022-12-17T23:55:41Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordStorageScheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG passwordAdminDN: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:41Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG [(0, 'aci', ['(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG New entry: cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Write Replication Changelog Configuration 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG ipapermissiontype: 2022-12-17T23:55:41Z DEBUG SYSTEM 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Write Replication Changelog Configuration 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG ipapermissiontype: 2022-12-17T23:55:41Z DEBUG SYSTEM 2022-12-17T23:55:41Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG config 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG nsslapdConfig 2022-12-17T23:55:41Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:41Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-betype: 2022-12-17T23:55:41Z DEBUG ldbm database 2022-12-17T23:55:41Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:41Z DEBUG cn=schema 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-plugin: 2022-12-17T23:55:41Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:41Z DEBUG 16384 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-port: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-localuser: 2022-12-17T23:55:41Z DEBUG dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordInHistory: 2022-12-17T23:55:41Z DEBUG 6 2022-12-17T23:55:41Z DEBUG passwordUnlock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordGraceLimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordMustChange: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:41Z DEBUG 100000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordWarning: 2022-12-17T23:55:41Z DEBUG 86400 2022-12-17T23:55:41Z DEBUG nsslapd-readonly: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:41Z DEBUG 16 2022-12-17T23:55:41Z DEBUG passwordLockout: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-localhost: 2022-12-17T23:55:41Z DEBUG master.redacted_domain.com 2022-12-17T23:55:41Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:41Z DEBUG 10000 2022-12-17T23:55:41Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:41Z DEBUG 40 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordMinLength: 2022-12-17T23:55:41Z DEBUG 8 2022-12-17T23:55:41Z DEBUG passwordMinDigits: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinAlphas: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinUppers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinLowers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinSpecials: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMin8bit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinCategories: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordPalindrome: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictCheck: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictPath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordUserAttributes: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordBadWords: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordMaxSequence: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:41Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:41Z DEBUG replication-only 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG passwordMaxFailure: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:41Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-security: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordMaxAge: 2022-12-17T23:55:41Z DEBUG 8640000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:41Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:41Z DEBUG passwordChange: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securePort: 2022-12-17T23:55:41Z DEBUG 636 2022-12-17T23:55:41Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:41Z DEBUG 64 2022-12-17T23:55:41Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordExp: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG day 2022-12-17T23:55:41Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-nagle: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:41Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:41Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:41Z DEBUG uidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:41Z DEBUG gidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:41Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-counters: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG passwordMinAge: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:41Z DEBUG 209715200 2022-12-17T23:55:41Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:41Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:41Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:41Z DEBUG 524288 2022-12-17T23:55:41Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:41Z DEBUG 1024 2022-12-17T23:55:41Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:41Z DEBUG allowed 2022-12-17T23:55:41Z DEBUG nsslapd-config: 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:41Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:41Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:41Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:41Z DEBUG /tmp 2022-12-17T23:55:41Z DEBUG nsslapd-certdir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:41Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:41Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rundir: 2022-12-17T23:55:41Z DEBUG /run/dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:41Z DEBUG 300000 2022-12-17T23:55:41Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-localssf: 2022-12-17T23:55:41Z DEBUG 71 2022-12-17T23:55:41Z DEBUG nsslapd-minssf: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:41Z DEBUG next 2022-12-17T23:55:41Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:41Z DEBUG warn 2022-12-17T23:55:41Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:41Z DEBUG 60 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:41Z DEBUG 20971520 2022-12-17T23:55:41Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:41Z DEBUG nolog 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:41Z DEBUG 128 2022-12-17T23:55:41Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:41Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:41Z DEBUG dirsrv-log 2022-12-17T23:55:41Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:41Z DEBUG process-safe 2022-12-17T23:55:41Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:41Z DEBUG 30 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:41Z DEBUG 300 2022-12-17T23:55:41Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordStorageScheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG passwordAdminDN: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:41Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG add: '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG add: updated value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=config 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG config 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG extensibleObject 2022-12-17T23:55:41Z DEBUG nsslapdConfig 2022-12-17T23:55:41Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:41Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-betype: 2022-12-17T23:55:41Z DEBUG ldbm database 2022-12-17T23:55:41Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:41Z DEBUG cn=schema 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-plugin: 2022-12-17T23:55:41Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:41Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:41Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:41Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:41Z DEBUG 16384 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-port: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-localuser: 2022-12-17T23:55:41Z DEBUG dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordInHistory: 2022-12-17T23:55:41Z DEBUG 6 2022-12-17T23:55:41Z DEBUG passwordUnlock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordGraceLimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG passwordMustChange: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:41Z DEBUG 100000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordWarning: 2022-12-17T23:55:41Z DEBUG 86400 2022-12-17T23:55:41Z DEBUG nsslapd-readonly: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:41Z DEBUG 16 2022-12-17T23:55:41Z DEBUG passwordLockout: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-localhost: 2022-12-17T23:55:41Z DEBUG master.redacted_domain.com 2022-12-17T23:55:41Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:41Z DEBUG 10000 2022-12-17T23:55:41Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:41Z DEBUG 40 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG passwordMinLength: 2022-12-17T23:55:41Z DEBUG 8 2022-12-17T23:55:41Z DEBUG passwordMinDigits: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinAlphas: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinUppers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinLowers: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinSpecials: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMin8bit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMinCategories: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG passwordPalindrome: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictCheck: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordDictPath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordUserAttributes: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordBadWords: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordMaxSequence: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:41Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:41Z DEBUG replication-only 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG passwordMaxFailure: 2022-12-17T23:55:41Z DEBUG 3 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:41Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-security: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordMaxAge: 2022-12-17T23:55:41Z DEBUG 8640000 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:41Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:41Z DEBUG passwordChange: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:41Z DEBUG 256 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securePort: 2022-12-17T23:55:41Z DEBUG 636 2022-12-17T23:55:41Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:41Z DEBUG 64 2022-12-17T23:55:41Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG passwordExp: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG day 2022-12-17T23:55:41Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-nagle: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:41Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:41Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:41Z DEBUG uidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:41Z DEBUG gidNumber 2022-12-17T23:55:41Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:41Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:41Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-counters: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:41Z DEBUG cn=Directory Manager 2022-12-17T23:55:41Z DEBUG passwordMinAge: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:41Z DEBUG 209715200 2022-12-17T23:55:41Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:41Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:41Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:41Z DEBUG 524288 2022-12-17T23:55:41Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:41Z DEBUG 1024 2022-12-17T23:55:41Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:41Z DEBUG allowed 2022-12-17T23:55:41Z DEBUG nsslapd-config: 2022-12-17T23:55:41Z DEBUG cn=config 2022-12-17T23:55:41Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:41Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:41Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:41Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:41Z DEBUG /tmp 2022-12-17T23:55:41Z DEBUG nsslapd-certdir: 2022-12-17T23:55:41Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:41Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:41Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:41Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:41Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rundir: 2022-12-17T23:55:41Z DEBUG /run/dirsrv 2022-12-17T23:55:41Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:41Z DEBUG 300000 2022-12-17T23:55:41Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-localssf: 2022-12-17T23:55:41Z DEBUG 71 2022-12-17T23:55:41Z DEBUG nsslapd-minssf: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:41Z DEBUG next 2022-12-17T23:55:41Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:41Z DEBUG warn 2022-12-17T23:55:41Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:41Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:41Z DEBUG 60 2022-12-17T23:55:41Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:41Z DEBUG 20971520 2022-12-17T23:55:41Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:41Z DEBUG nolog 2022-12-17T23:55:41Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:41Z DEBUG 2097152 2022-12-17T23:55:41Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:41Z DEBUG 128 2022-12-17T23:55:41Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:41Z DEBUG -10 2022-12-17T23:55:41Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:41Z DEBUG -1 2022-12-17T23:55:41Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 2 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:41Z DEBUG 600 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:41Z DEBUG 0 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:41Z DEBUG 500 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:41Z DEBUG 100 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:41Z DEBUG 1 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:41Z DEBUG 10 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:41Z DEBUG month 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:41Z DEBUG 5 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:41Z DEBUG week 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:41Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:41Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:41Z DEBUG dirsrv-log 2022-12-17T23:55:41Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:41Z DEBUG none 2022-12-17T23:55:41Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:41Z DEBUG process-safe 2022-12-17T23:55:41Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:41Z DEBUG 3600 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:41Z DEBUG 30 2022-12-17T23:55:41Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:41Z DEBUG 300 2022-12-17T23:55:41Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG passwordStorageScheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG passwordAdminDN: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:41Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:41Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:41Z DEBUG on 2022-12-17T23:55:41Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:41Z DEBUG off 2022-12-17T23:55:41Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:41Z DEBUG 2022-12-17T23:55:41Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:41Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:41Z DEBUG aci: 2022-12-17T23:55:41Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:41Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG (targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:41Z DEBUG [(0, 'aci', ['(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Updated 1 2022-12-17T23:55:41Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:41Z DEBUG Done 2022-12-17T23:55:41Z DEBUG New entry: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Initial value 2022-12-17T23:55:41Z DEBUG dn: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:41Z DEBUG cn: 2022-12-17T23:55:41Z DEBUG Modify PassSync Managers Configuration 2022-12-17T23:55:41Z DEBUG member: 2022-12-17T23:55:41Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG ipapermissiontype: 2022-12-17T23:55:41Z DEBUG SYSTEM 2022-12-17T23:55:41Z DEBUG --------------------------------------------- 2022-12-17T23:55:41Z DEBUG Final value after applying updates 2022-12-17T23:55:41Z DEBUG dn: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:41Z DEBUG objectClass: 2022-12-17T23:55:41Z DEBUG groupofnames 2022-12-17T23:55:41Z DEBUG ipapermission 2022-12-17T23:55:41Z DEBUG top 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG Modify PassSync Managers Configuration 2022-12-17T23:55:42Z DEBUG member: 2022-12-17T23:55:42Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG ipapermissiontype: 2022-12-17T23:55:42Z DEBUG SYSTEM 2022-12-17T23:55:42Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=config 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG config 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG extensibleObject 2022-12-17T23:55:42Z DEBUG nsslapdConfig 2022-12-17T23:55:42Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:42Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-betype: 2022-12-17T23:55:42Z DEBUG ldbm database 2022-12-17T23:55:42Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:42Z DEBUG cn=schema 2022-12-17T23:55:42Z DEBUG cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-plugin: 2022-12-17T23:55:42Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 10 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:42Z DEBUG 16384 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-port: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-localuser: 2022-12-17T23:55:42Z DEBUG dirsrv 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG passwordInHistory: 2022-12-17T23:55:42Z DEBUG 6 2022-12-17T23:55:42Z DEBUG passwordUnlock: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordGraceLimit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG passwordMustChange: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:42Z DEBUG 100000 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG passwordWarning: 2022-12-17T23:55:42Z DEBUG 86400 2022-12-17T23:55:42Z DEBUG nsslapd-readonly: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:42Z DEBUG 16 2022-12-17T23:55:42Z DEBUG passwordLockout: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-localhost: 2022-12-17T23:55:42Z DEBUG master.redacted_domain.com 2022-12-17T23:55:42Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:42Z DEBUG 10000 2022-12-17T23:55:42Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:42Z DEBUG 40 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG passwordMinLength: 2022-12-17T23:55:42Z DEBUG 8 2022-12-17T23:55:42Z DEBUG passwordMinDigits: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinAlphas: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinUppers: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinLowers: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinSpecials: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMin8bit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinCategories: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG passwordPalindrome: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordDictCheck: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordDictPath: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordUserAttributes: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordBadWords: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordMaxSequence: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:42Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:42Z DEBUG replication-only 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 500 2022-12-17T23:55:42Z DEBUG passwordMaxFailure: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:42Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-security: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordMaxAge: 2022-12-17T23:55:42Z DEBUG 8640000 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:42Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:42Z DEBUG passwordChange: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:42Z DEBUG 256 2022-12-17T23:55:42Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:42Z DEBUG 256 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-securePort: 2022-12-17T23:55:42Z DEBUG 636 2022-12-17T23:55:42Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:42Z DEBUG 64 2022-12-17T23:55:42Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordExp: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG day 2022-12-17T23:55:42Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-nagle: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:42Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:42Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:42Z DEBUG cn=Directory Manager 2022-12-17T23:55:42Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:42Z DEBUG uidNumber 2022-12-17T23:55:42Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:42Z DEBUG gidNumber 2022-12-17T23:55:42Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:42Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:42Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:42Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG nsslapd-counters: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:42Z DEBUG cn=Directory Manager 2022-12-17T23:55:42Z DEBUG passwordMinAge: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:42Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:42Z DEBUG 209715200 2022-12-17T23:55:42Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:42Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:42Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:42Z DEBUG 524288 2022-12-17T23:55:42Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:42Z DEBUG 1024 2022-12-17T23:55:42Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:42Z DEBUG allowed 2022-12-17T23:55:42Z DEBUG nsslapd-config: 2022-12-17T23:55:42Z DEBUG cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:42Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:42Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:42Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:42Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:42Z DEBUG /tmp 2022-12-17T23:55:42Z DEBUG nsslapd-certdir: 2022-12-17T23:55:42Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:42Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:42Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:42Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:42Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-rundir: 2022-12-17T23:55:42Z DEBUG /run/dirsrv 2022-12-17T23:55:42Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:42Z DEBUG 300000 2022-12-17T23:55:42Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-localssf: 2022-12-17T23:55:42Z DEBUG 71 2022-12-17T23:55:42Z DEBUG nsslapd-minssf: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:42Z DEBUG next 2022-12-17T23:55:42Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:42Z DEBUG warn 2022-12-17T23:55:42Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:42Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:42Z DEBUG 60 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:42Z DEBUG 20971520 2022-12-17T23:55:42Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:42Z DEBUG nolog 2022-12-17T23:55:42Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:42Z DEBUG 128 2022-12-17T23:55:42Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 500 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 10 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:42Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:42Z DEBUG dirsrv-log 2022-12-17T23:55:42Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:42Z DEBUG none 2022-12-17T23:55:42Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:42Z DEBUG process-safe 2022-12-17T23:55:42Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:42Z DEBUG 30 2022-12-17T23:55:42Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:42Z DEBUG 300 2022-12-17T23:55:42Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordStorageScheme: 2022-12-17T23:55:42Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:42Z DEBUG passwordAdminDN: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:42Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:42Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:42Z DEBUG aci: 2022-12-17T23:55:42Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:42Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG add: '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:42Z DEBUG add: updated value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=config 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG config 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG extensibleObject 2022-12-17T23:55:42Z DEBUG nsslapdConfig 2022-12-17T23:55:42Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:42Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-betype: 2022-12-17T23:55:42Z DEBUG ldbm database 2022-12-17T23:55:42Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:42Z DEBUG cn=schema 2022-12-17T23:55:42Z DEBUG cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-plugin: 2022-12-17T23:55:42Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 10 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:42Z DEBUG 16384 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-port: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-localuser: 2022-12-17T23:55:42Z DEBUG dirsrv 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG passwordInHistory: 2022-12-17T23:55:42Z DEBUG 6 2022-12-17T23:55:42Z DEBUG passwordUnlock: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordGraceLimit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG passwordMustChange: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:42Z DEBUG 100000 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG passwordWarning: 2022-12-17T23:55:42Z DEBUG 86400 2022-12-17T23:55:42Z DEBUG nsslapd-readonly: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:42Z DEBUG 16 2022-12-17T23:55:42Z DEBUG passwordLockout: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-localhost: 2022-12-17T23:55:42Z DEBUG master.redacted_domain.com 2022-12-17T23:55:42Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:42Z DEBUG 10000 2022-12-17T23:55:42Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:42Z DEBUG 40 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG passwordMinLength: 2022-12-17T23:55:42Z DEBUG 8 2022-12-17T23:55:42Z DEBUG passwordMinDigits: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinAlphas: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinUppers: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinLowers: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinSpecials: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMin8bit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinCategories: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG passwordPalindrome: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordDictCheck: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordDictPath: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordUserAttributes: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordBadWords: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordMaxSequence: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:42Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:42Z DEBUG replication-only 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 500 2022-12-17T23:55:42Z DEBUG passwordMaxFailure: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:42Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-security: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordMaxAge: 2022-12-17T23:55:42Z DEBUG 8640000 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:42Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:42Z DEBUG passwordChange: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:42Z DEBUG 256 2022-12-17T23:55:42Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:42Z DEBUG 256 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-securePort: 2022-12-17T23:55:42Z DEBUG 636 2022-12-17T23:55:42Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:42Z DEBUG 64 2022-12-17T23:55:42Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordExp: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG day 2022-12-17T23:55:42Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-nagle: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:42Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:42Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:42Z DEBUG cn=Directory Manager 2022-12-17T23:55:42Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:42Z DEBUG uidNumber 2022-12-17T23:55:42Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:42Z DEBUG gidNumber 2022-12-17T23:55:42Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:42Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:42Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:42Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG nsslapd-counters: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:42Z DEBUG cn=Directory Manager 2022-12-17T23:55:42Z DEBUG passwordMinAge: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:42Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:42Z DEBUG 209715200 2022-12-17T23:55:42Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:42Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:42Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:42Z DEBUG 524288 2022-12-17T23:55:42Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:42Z DEBUG 1024 2022-12-17T23:55:42Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:42Z DEBUG allowed 2022-12-17T23:55:42Z DEBUG nsslapd-config: 2022-12-17T23:55:42Z DEBUG cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:42Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:42Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:42Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:42Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:42Z DEBUG /tmp 2022-12-17T23:55:42Z DEBUG nsslapd-certdir: 2022-12-17T23:55:42Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:42Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:42Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:42Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:42Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-rundir: 2022-12-17T23:55:42Z DEBUG /run/dirsrv 2022-12-17T23:55:42Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:42Z DEBUG 300000 2022-12-17T23:55:42Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-localssf: 2022-12-17T23:55:42Z DEBUG 71 2022-12-17T23:55:42Z DEBUG nsslapd-minssf: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:42Z DEBUG next 2022-12-17T23:55:42Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:42Z DEBUG warn 2022-12-17T23:55:42Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:42Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:42Z DEBUG 60 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:42Z DEBUG 20971520 2022-12-17T23:55:42Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:42Z DEBUG nolog 2022-12-17T23:55:42Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:42Z DEBUG 128 2022-12-17T23:55:42Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 500 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 10 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:42Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:42Z DEBUG dirsrv-log 2022-12-17T23:55:42Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:42Z DEBUG none 2022-12-17T23:55:42Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:42Z DEBUG process-safe 2022-12-17T23:55:42Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:42Z DEBUG 30 2022-12-17T23:55:42Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:42Z DEBUG 300 2022-12-17T23:55:42Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordStorageScheme: 2022-12-17T23:55:42Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:42Z DEBUG passwordAdminDN: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:42Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:42Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:42Z DEBUG aci: 2022-12-17T23:55:42Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:42Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG [(0, 'aci', ['(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:42Z DEBUG Updated 1 2022-12-17T23:55:42Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:42Z DEBUG Done 2022-12-17T23:55:42Z DEBUG New entry: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG groupofnames 2022-12-17T23:55:42Z DEBUG ipapermission 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG Read LDBM Database Configuration 2022-12-17T23:55:42Z DEBUG member: 2022-12-17T23:55:42Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG ipapermissiontype: 2022-12-17T23:55:42Z DEBUG SYSTEM 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG groupofnames 2022-12-17T23:55:42Z DEBUG ipapermission 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG Read LDBM Database Configuration 2022-12-17T23:55:42Z DEBUG member: 2022-12-17T23:55:42Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG ipapermissiontype: 2022-12-17T23:55:42Z DEBUG SYSTEM 2022-12-17T23:55:42Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=config 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG config 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG extensibleObject 2022-12-17T23:55:42Z DEBUG nsslapdConfig 2022-12-17T23:55:42Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:42Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-betype: 2022-12-17T23:55:42Z DEBUG ldbm database 2022-12-17T23:55:42Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:42Z DEBUG cn=schema 2022-12-17T23:55:42Z DEBUG cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-plugin: 2022-12-17T23:55:42Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 10 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:42Z DEBUG 16384 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-port: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-localuser: 2022-12-17T23:55:42Z DEBUG dirsrv 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG passwordInHistory: 2022-12-17T23:55:42Z DEBUG 6 2022-12-17T23:55:42Z DEBUG passwordUnlock: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordGraceLimit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG passwordMustChange: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:42Z DEBUG 100000 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG passwordWarning: 2022-12-17T23:55:42Z DEBUG 86400 2022-12-17T23:55:42Z DEBUG nsslapd-readonly: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:42Z DEBUG 16 2022-12-17T23:55:42Z DEBUG passwordLockout: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-localhost: 2022-12-17T23:55:42Z DEBUG master.redacted_domain.com 2022-12-17T23:55:42Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:42Z DEBUG 10000 2022-12-17T23:55:42Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:42Z DEBUG 40 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG passwordMinLength: 2022-12-17T23:55:42Z DEBUG 8 2022-12-17T23:55:42Z DEBUG passwordMinDigits: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinAlphas: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinUppers: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinLowers: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinSpecials: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMin8bit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinCategories: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG passwordPalindrome: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordDictCheck: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordDictPath: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordUserAttributes: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordBadWords: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordMaxSequence: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:42Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:42Z DEBUG replication-only 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 500 2022-12-17T23:55:42Z DEBUG passwordMaxFailure: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:42Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-security: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordMaxAge: 2022-12-17T23:55:42Z DEBUG 8640000 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:42Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:42Z DEBUG passwordChange: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:42Z DEBUG 256 2022-12-17T23:55:42Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:42Z DEBUG 256 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-securePort: 2022-12-17T23:55:42Z DEBUG 636 2022-12-17T23:55:42Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:42Z DEBUG 64 2022-12-17T23:55:42Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordExp: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG day 2022-12-17T23:55:42Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-nagle: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:42Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:42Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:42Z DEBUG cn=Directory Manager 2022-12-17T23:55:42Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:42Z DEBUG uidNumber 2022-12-17T23:55:42Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:42Z DEBUG gidNumber 2022-12-17T23:55:42Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:42Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:42Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:42Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG nsslapd-counters: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:42Z DEBUG cn=Directory Manager 2022-12-17T23:55:42Z DEBUG passwordMinAge: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:42Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:42Z DEBUG 209715200 2022-12-17T23:55:42Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:42Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:42Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:42Z DEBUG 524288 2022-12-17T23:55:42Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:42Z DEBUG 1024 2022-12-17T23:55:42Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:42Z DEBUG allowed 2022-12-17T23:55:42Z DEBUG nsslapd-config: 2022-12-17T23:55:42Z DEBUG cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:42Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:42Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:42Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:42Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:42Z DEBUG /tmp 2022-12-17T23:55:42Z DEBUG nsslapd-certdir: 2022-12-17T23:55:42Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:42Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:42Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:42Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:42Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-rundir: 2022-12-17T23:55:42Z DEBUG /run/dirsrv 2022-12-17T23:55:42Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:42Z DEBUG 300000 2022-12-17T23:55:42Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-localssf: 2022-12-17T23:55:42Z DEBUG 71 2022-12-17T23:55:42Z DEBUG nsslapd-minssf: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:42Z DEBUG next 2022-12-17T23:55:42Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:42Z DEBUG warn 2022-12-17T23:55:42Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:42Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:42Z DEBUG 60 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:42Z DEBUG 20971520 2022-12-17T23:55:42Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:42Z DEBUG nolog 2022-12-17T23:55:42Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:42Z DEBUG 128 2022-12-17T23:55:42Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 500 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 10 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:42Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:42Z DEBUG dirsrv-log 2022-12-17T23:55:42Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:42Z DEBUG none 2022-12-17T23:55:42Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:42Z DEBUG process-safe 2022-12-17T23:55:42Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:42Z DEBUG 30 2022-12-17T23:55:42Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:42Z DEBUG 300 2022-12-17T23:55:42Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordStorageScheme: 2022-12-17T23:55:42Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:42Z DEBUG passwordAdminDN: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:42Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:42Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:42Z DEBUG aci: 2022-12-17T23:55:42Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:42Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG add: '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:42Z DEBUG add: updated value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=config 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG config 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG extensibleObject 2022-12-17T23:55:42Z DEBUG nsslapdConfig 2022-12-17T23:55:42Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:42Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-betype: 2022-12-17T23:55:42Z DEBUG ldbm database 2022-12-17T23:55:42Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:42Z DEBUG cn=schema 2022-12-17T23:55:42Z DEBUG cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-plugin: 2022-12-17T23:55:42Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 10 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:42Z DEBUG 16384 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-port: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-localuser: 2022-12-17T23:55:42Z DEBUG dirsrv 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG passwordInHistory: 2022-12-17T23:55:42Z DEBUG 6 2022-12-17T23:55:42Z DEBUG passwordUnlock: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordGraceLimit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG passwordMustChange: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:42Z DEBUG 100000 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG passwordWarning: 2022-12-17T23:55:42Z DEBUG 86400 2022-12-17T23:55:42Z DEBUG nsslapd-readonly: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:42Z DEBUG 16 2022-12-17T23:55:42Z DEBUG passwordLockout: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-localhost: 2022-12-17T23:55:42Z DEBUG master.redacted_domain.com 2022-12-17T23:55:42Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:42Z DEBUG 10000 2022-12-17T23:55:42Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:42Z DEBUG 40 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG passwordMinLength: 2022-12-17T23:55:42Z DEBUG 8 2022-12-17T23:55:42Z DEBUG passwordMinDigits: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinAlphas: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinUppers: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinLowers: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinSpecials: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMin8bit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinCategories: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG passwordPalindrome: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordDictCheck: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordDictPath: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordUserAttributes: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordBadWords: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordMaxSequence: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:42Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:42Z DEBUG replication-only 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 500 2022-12-17T23:55:42Z DEBUG passwordMaxFailure: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:42Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-security: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordMaxAge: 2022-12-17T23:55:42Z DEBUG 8640000 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:42Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:42Z DEBUG passwordChange: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:42Z DEBUG 256 2022-12-17T23:55:42Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:42Z DEBUG 256 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-securePort: 2022-12-17T23:55:42Z DEBUG 636 2022-12-17T23:55:42Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:42Z DEBUG 64 2022-12-17T23:55:42Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordExp: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG day 2022-12-17T23:55:42Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-nagle: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:42Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:42Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:42Z DEBUG cn=Directory Manager 2022-12-17T23:55:42Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:42Z DEBUG uidNumber 2022-12-17T23:55:42Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:42Z DEBUG gidNumber 2022-12-17T23:55:42Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:42Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:42Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:42Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG nsslapd-counters: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:42Z DEBUG cn=Directory Manager 2022-12-17T23:55:42Z DEBUG passwordMinAge: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:42Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:42Z DEBUG 209715200 2022-12-17T23:55:42Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:42Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:42Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:42Z DEBUG 524288 2022-12-17T23:55:42Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:42Z DEBUG 1024 2022-12-17T23:55:42Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:42Z DEBUG allowed 2022-12-17T23:55:42Z DEBUG nsslapd-config: 2022-12-17T23:55:42Z DEBUG cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:42Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:42Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:42Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:42Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:42Z DEBUG /tmp 2022-12-17T23:55:42Z DEBUG nsslapd-certdir: 2022-12-17T23:55:42Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:42Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:42Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:42Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:42Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-rundir: 2022-12-17T23:55:42Z DEBUG /run/dirsrv 2022-12-17T23:55:42Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:42Z DEBUG 300000 2022-12-17T23:55:42Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-localssf: 2022-12-17T23:55:42Z DEBUG 71 2022-12-17T23:55:42Z DEBUG nsslapd-minssf: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:42Z DEBUG next 2022-12-17T23:55:42Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:42Z DEBUG warn 2022-12-17T23:55:42Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:42Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:42Z DEBUG 60 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:42Z DEBUG 20971520 2022-12-17T23:55:42Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:42Z DEBUG nolog 2022-12-17T23:55:42Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:42Z DEBUG 128 2022-12-17T23:55:42Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 500 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 10 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:42Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:42Z DEBUG dirsrv-log 2022-12-17T23:55:42Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:42Z DEBUG none 2022-12-17T23:55:42Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:42Z DEBUG process-safe 2022-12-17T23:55:42Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:42Z DEBUG 30 2022-12-17T23:55:42Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:42Z DEBUG 300 2022-12-17T23:55:42Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordStorageScheme: 2022-12-17T23:55:42Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:42Z DEBUG passwordAdminDN: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:42Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:42Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:42Z DEBUG aci: 2022-12-17T23:55:42Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:42Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG [(0, 'aci', ['(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:42Z DEBUG Updated 1 2022-12-17T23:55:42Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:42Z DEBUG Done 2022-12-17T23:55:42Z DEBUG New entry: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG groupofnames 2022-12-17T23:55:42Z DEBUG ipapermission 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG Add Configuration Sub-Entries 2022-12-17T23:55:42Z DEBUG member: 2022-12-17T23:55:42Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG ipapermissiontype: 2022-12-17T23:55:42Z DEBUG SYSTEM 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG groupofnames 2022-12-17T23:55:42Z DEBUG ipapermission 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG Add Configuration Sub-Entries 2022-12-17T23:55:42Z DEBUG member: 2022-12-17T23:55:42Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG ipapermissiontype: 2022-12-17T23:55:42Z DEBUG SYSTEM 2022-12-17T23:55:42Z DEBUG Updating existing entry: cn=config 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=config 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG config 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG extensibleObject 2022-12-17T23:55:42Z DEBUG nsslapdConfig 2022-12-17T23:55:42Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:42Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-betype: 2022-12-17T23:55:42Z DEBUG ldbm database 2022-12-17T23:55:42Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:42Z DEBUG cn=schema 2022-12-17T23:55:42Z DEBUG cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-plugin: 2022-12-17T23:55:42Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 10 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:42Z DEBUG 16384 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-port: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-localuser: 2022-12-17T23:55:42Z DEBUG dirsrv 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG passwordInHistory: 2022-12-17T23:55:42Z DEBUG 6 2022-12-17T23:55:42Z DEBUG passwordUnlock: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordGraceLimit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG passwordMustChange: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:42Z DEBUG 100000 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG passwordWarning: 2022-12-17T23:55:42Z DEBUG 86400 2022-12-17T23:55:42Z DEBUG nsslapd-readonly: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:42Z DEBUG 16 2022-12-17T23:55:42Z DEBUG passwordLockout: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-localhost: 2022-12-17T23:55:42Z DEBUG master.redacted_domain.com 2022-12-17T23:55:42Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:42Z DEBUG 10000 2022-12-17T23:55:42Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:42Z DEBUG 40 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG passwordMinLength: 2022-12-17T23:55:42Z DEBUG 8 2022-12-17T23:55:42Z DEBUG passwordMinDigits: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinAlphas: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinUppers: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinLowers: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinSpecials: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMin8bit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinCategories: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG passwordPalindrome: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordDictCheck: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordDictPath: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordUserAttributes: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordBadWords: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordMaxSequence: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:42Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:42Z DEBUG replication-only 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 500 2022-12-17T23:55:42Z DEBUG passwordMaxFailure: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:42Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-security: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordMaxAge: 2022-12-17T23:55:42Z DEBUG 8640000 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:42Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:42Z DEBUG passwordChange: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:42Z DEBUG 256 2022-12-17T23:55:42Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:42Z DEBUG 256 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-securePort: 2022-12-17T23:55:42Z DEBUG 636 2022-12-17T23:55:42Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:42Z DEBUG 64 2022-12-17T23:55:42Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordExp: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG day 2022-12-17T23:55:42Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-nagle: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:42Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:42Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:42Z DEBUG cn=Directory Manager 2022-12-17T23:55:42Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:42Z DEBUG uidNumber 2022-12-17T23:55:42Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:42Z DEBUG gidNumber 2022-12-17T23:55:42Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:42Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:42Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:42Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG nsslapd-counters: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:42Z DEBUG cn=Directory Manager 2022-12-17T23:55:42Z DEBUG passwordMinAge: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:42Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:42Z DEBUG 209715200 2022-12-17T23:55:42Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:42Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:42Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:42Z DEBUG 524288 2022-12-17T23:55:42Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:42Z DEBUG 1024 2022-12-17T23:55:42Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:42Z DEBUG allowed 2022-12-17T23:55:42Z DEBUG nsslapd-config: 2022-12-17T23:55:42Z DEBUG cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:42Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:42Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:42Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:42Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:42Z DEBUG /tmp 2022-12-17T23:55:42Z DEBUG nsslapd-certdir: 2022-12-17T23:55:42Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:42Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:42Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:42Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:42Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-rundir: 2022-12-17T23:55:42Z DEBUG /run/dirsrv 2022-12-17T23:55:42Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:42Z DEBUG 300000 2022-12-17T23:55:42Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-localssf: 2022-12-17T23:55:42Z DEBUG 71 2022-12-17T23:55:42Z DEBUG nsslapd-minssf: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:42Z DEBUG next 2022-12-17T23:55:42Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:42Z DEBUG warn 2022-12-17T23:55:42Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:42Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:42Z DEBUG 60 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:42Z DEBUG 20971520 2022-12-17T23:55:42Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:42Z DEBUG nolog 2022-12-17T23:55:42Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:42Z DEBUG 128 2022-12-17T23:55:42Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 500 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 10 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:42Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:42Z DEBUG dirsrv-log 2022-12-17T23:55:42Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:42Z DEBUG none 2022-12-17T23:55:42Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:42Z DEBUG process-safe 2022-12-17T23:55:42Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:42Z DEBUG 30 2022-12-17T23:55:42Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:42Z DEBUG 300 2022-12-17T23:55:42Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordStorageScheme: 2022-12-17T23:55:42Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:42Z DEBUG passwordAdminDN: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:42Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:42Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:42Z DEBUG aci: 2022-12-17T23:55:42Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:42Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG add: '(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:42Z DEBUG add: updated value ['(targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=config 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG config 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG extensibleObject 2022-12-17T23:55:42Z DEBUG nsslapdConfig 2022-12-17T23:55:42Z DEBUG nsslapd-backendconfig: 2022-12-17T23:55:42Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-betype: 2022-12-17T23:55:42Z DEBUG ldbm database 2022-12-17T23:55:42Z DEBUG nsslapd-privatenamespaces: 2022-12-17T23:55:42Z DEBUG cn=schema 2022-12-17T23:55:42Z DEBUG cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-plugin: 2022-12-17T23:55:42Z DEBUG cn=binary syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=country string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=entryuuid_syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=fax syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=guide syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integer syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=oid syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=space insensitive string syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uuidmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uuidorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-requiresrestart: 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-port 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-secureport 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-ldapifilepath 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-ldapilisten 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-workingdir 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-plugin 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-sslclientauth 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogdir 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogsuffix 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogmaxentries 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-changelogmaxage 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-db-locks 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-maxdescriptors 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-numlisteners 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-return-exact-case 2022-12-17T23:55:42Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2022-12-17T23:55:42Z DEBUG cn=config,cn=ldbm:nsslapd-backend-implement 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nssslclientauth 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nsssl2 2022-12-17T23:55:42Z DEBUG cn=encryption,cn=config:nsssl3 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 10 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-level: 2022-12-17T23:55:42Z DEBUG 16384 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-compress: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-compress: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-port: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-workingdir: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-maxthreadsperconn: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-localuser: 2022-12-17T23:55:42Z DEBUG dirsrv 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG passwordInHistory: 2022-12-17T23:55:42Z DEBUG 6 2022-12-17T23:55:42Z DEBUG passwordUnlock: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordGraceLimit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG passwordMustChange: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-pwpolicy-local: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-pwpolicy-inherit-global: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-sizelimit: 2022-12-17T23:55:42Z DEBUG 100000 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG passwordWarning: 2022-12-17T23:55:42Z DEBUG 86400 2022-12-17T23:55:42Z DEBUG nsslapd-readonly: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-sasl-mapping-fallback: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-threadnumber: 2022-12-17T23:55:42Z DEBUG 16 2022-12-17T23:55:42Z DEBUG passwordLockout: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-enquote-sup-oc: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-localhost: 2022-12-17T23:55:42Z DEBUG master.redacted_domain.com 2022-12-17T23:55:42Z DEBUG nsslapd-ioblocktimeout: 2022-12-17T23:55:42Z DEBUG 10000 2022-12-17T23:55:42Z DEBUG nsslapd-max-filter-nest-level: 2022-12-17T23:55:42Z DEBUG 40 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG passwordMinLength: 2022-12-17T23:55:42Z DEBUG 8 2022-12-17T23:55:42Z DEBUG passwordMinDigits: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinAlphas: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinUppers: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinLowers: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinSpecials: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMin8bit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxRepeats: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMinCategories: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG passwordMinTokenLength: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG passwordPalindrome: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordDictCheck: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordDictPath: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordUserAttributes: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordBadWords: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordMaxSequence: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxSeqSets: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG passwordMaxClassChars: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/errors 2022-12-17T23:55:42Z DEBUG nsslapd-external-libs-debug-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-schemacheck: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-schemamod: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-syntaxcheck: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-syntaxlogging: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-dn-validate-strict: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-ds4-compatible-schema: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-schemareplace: 2022-12-17T23:55:42Z DEBUG replication-only 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 500 2022-12-17T23:55:42Z DEBUG passwordMaxFailure: 2022-12-17T23:55:42Z DEBUG 3 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/access 2022-12-17T23:55:42Z DEBUG nsslapd-lastmod: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-security: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordMaxAge: 2022-12-17T23:55:42Z DEBUG 8640000 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG passwordResetFailureCount: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG passwordTPRMaxUse: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordTPRDelayExpireAt: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordTPRDelayValidFrom: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG passwordIsGlobalPolicy: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordLegacyPolicy: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordTrackUpdateTime: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-groupevalnestlevel: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-rootpw: 2022-12-17T23:55:42Z DEBUG {PBKDF2-SHA512}10000$pISGwx13BxL0yKplNS5ekYjUpFfDCps8$LTAaEbabsd5r4Mn+l1AuJHimn9KvHwc0Z1iVsWfEJVLQZ3NphMK1/X935mha4TKVUy14lEi0Njbf8yYngsyr/Q== 2022-12-17T23:55:42Z DEBUG passwordChange: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-level: 2022-12-17T23:55:42Z DEBUG 256 2022-12-17T23:55:42Z DEBUG nsslapd-statlog-level: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-level: 2022-12-17T23:55:42Z DEBUG 256 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-securePort: 2022-12-17T23:55:42Z DEBUG 636 2022-12-17T23:55:42Z DEBUG nsslapd-certmap-basedn: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-timelimit: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-reservedescriptors: 2022-12-17T23:55:42Z DEBUG 64 2022-12-17T23:55:42Z DEBUG nsslapd-svrtab: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG passwordExp: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG passwordSendExpiringTime: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-accesscontrol: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG day 2022-12-17T23:55:42Z DEBUG passwordLockoutDuration: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-idletimeout: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-nagle: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logging-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-display-attrs: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logbuffering: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logbuffering: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-csnlogging: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-allow-hashed-passwords: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordCheckSyntax: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-listenhost: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-snmp-index: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-ldapifilepath: 2022-12-17T23:55:42Z DEBUG /run/slapd-REDACTED_DOMAIN-COM.socket 2022-12-17T23:55:42Z DEBUG nsslapd-ldapilisten: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapiautobind: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapimaprootdn: 2022-12-17T23:55:42Z DEBUG cn=Directory Manager 2022-12-17T23:55:42Z DEBUG nsslapd-ldapimaptoentries: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapiuidnumbertype: 2022-12-17T23:55:42Z DEBUG uidNumber 2022-12-17T23:55:42Z DEBUG nsslapd-ldapigidnumbertype: 2022-12-17T23:55:42Z DEBUG gidNumber 2022-12-17T23:55:42Z DEBUG nsslapd-ldapientrysearchbase: 2022-12-17T23:55:42Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-ldapidnmappingbase: 2022-12-17T23:55:42Z DEBUG cn=auto_bind,cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-anonlimitsdn: 2022-12-17T23:55:42Z DEBUG cn=anonymous-limits,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG nsslapd-counters: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-securelistenhost: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-rootdn: 2022-12-17T23:55:42Z DEBUG cn=Directory Manager 2022-12-17T23:55:42Z DEBUG passwordMinAge: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:42Z DEBUG nsslapd-return-exact-case: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-result-tweak: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-plugin-binddn-tracking: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-moddn-aci: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-targetfilter-cache: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-attribute-name-exceptions: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-maxbersize: 2022-12-17T23:55:42Z DEBUG 209715200 2022-12-17T23:55:42Z DEBUG nsslapd-maxsasliosize: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-versionstring: 2022-12-17T23:55:42Z DEBUG 389-Directory/2.2.4 2022-12-17T23:55:42Z DEBUG nsslapd-referralmode: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-maxdescriptors: 2022-12-17T23:55:42Z DEBUG 524288 2022-12-17T23:55:42Z DEBUG nsslapd-conntablesize: 2022-12-17T23:55:42Z DEBUG 1024 2022-12-17T23:55:42Z DEBUG nsslapd-SSLclientAuth: 2022-12-17T23:55:42Z DEBUG allowed 2022-12-17T23:55:42Z DEBUG nsslapd-config: 2022-12-17T23:55:42Z DEBUG cn=config 2022-12-17T23:55:42Z DEBUG nsslapd-instancedir: 2022-12-17T23:55:42Z DEBUG /usr/lib64/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-schemadir: 2022-12-17T23:55:42Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM/schema 2022-12-17T23:55:42Z DEBUG nsslapd-lockdir: 2022-12-17T23:55:42Z DEBUG /run/lock/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-tmpdir: 2022-12-17T23:55:42Z DEBUG /tmp 2022-12-17T23:55:42Z DEBUG nsslapd-certdir: 2022-12-17T23:55:42Z DEBUG /etc/dirsrv/slapd-REDACTED_DOMAIN-COM 2022-12-17T23:55:42Z DEBUG nsslapd-ldifdir: 2022-12-17T23:55:42Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/ldif 2022-12-17T23:55:42Z DEBUG nsslapd-bakdir: 2022-12-17T23:55:42Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/bak 2022-12-17T23:55:42Z DEBUG nsslapd-saslpath: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-rundir: 2022-12-17T23:55:42Z DEBUG /run/dirsrv 2022-12-17T23:55:42Z DEBUG nsslapd-rewrite-rfc1274: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-outbound-ldap-io-timeout: 2022-12-17T23:55:42Z DEBUG 300000 2022-12-17T23:55:42Z DEBUG nsslapd-allow-unauthenticated-binds: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-require-secure-binds: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-allow-anonymous-access: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-localssf: 2022-12-17T23:55:42Z DEBUG 71 2022-12-17T23:55:42Z DEBUG nsslapd-minssf: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-minssf-exclude-rootdse: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-force-sasl-external: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-entryusn-global: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-entryusn-import-initval: 2022-12-17T23:55:42Z DEBUG next 2022-12-17T23:55:42Z DEBUG nsslapd-validate-cert: 2022-12-17T23:55:42Z DEBUG warn 2022-12-17T23:55:42Z DEBUG nsslapd-pagedsizelimit: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-defaultnamingcontext: 2022-12-17T23:55:42Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-readonly-on-threshold: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-threshold: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-grace-period: 2022-12-17T23:55:42Z DEBUG 60 2022-12-17T23:55:42Z DEBUG nsslapd-disk-monitoring-logging-critical: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-ndn-cache-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ndn-cache-max-size: 2022-12-17T23:55:42Z DEBUG 20971520 2022-12-17T23:55:42Z DEBUG nsslapd-allowed-sasl-mechanisms: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ignore-virtual-attrs: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-unhashed-pw-switch: 2022-12-17T23:55:42Z DEBUG nolog 2022-12-17T23:55:42Z DEBUG nsslapd-sasl-max-buffer-size: 2022-12-17T23:55:42Z DEBUG 2097152 2022-12-17T23:55:42Z DEBUG nsslapd-search-return-original-type-switch: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-enable-turbo-mode: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-connection-buffer: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-connection-nocanon: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-plugin-logging: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-listen-backlog-size: 2022-12-17T23:55:42Z DEBUG 128 2022-12-17T23:55:42Z DEBUG nsslapd-dynamic-plugins: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-mxfast: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-trim-threshold: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-malloc-mmap-threshold: 2022-12-17T23:55:42Z DEBUG -10 2022-12-17T23:55:42Z DEBUG nsslapd-ignore-time-skew: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-global-backend-lock: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-maxsimplepaged-per-conn: 2022-12-17T23:55:42Z DEBUG -1 2022-12-17T23:55:42Z DEBUG nsslapd-enable-nunc-stans: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 2 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logging-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/audit 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-mode: 2022-12-17T23:55:42Z DEBUG 600 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsync-enabled: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsynchour: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationsyncmin: 2022-12-17T23:55:42Z DEBUG 0 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logmaxdiskspace: 2022-12-17T23:55:42Z DEBUG 500 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-maxlogsize: 2022-12-17T23:55:42Z DEBUG 100 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logexpirationtime: 2022-12-17T23:55:42Z DEBUG 1 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-maxlogsperdir: 2022-12-17T23:55:42Z DEBUG 10 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logging-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logexpirationtimeunit: 2022-12-17T23:55:42Z DEBUG month 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logminfreediskspace: 2022-12-17T23:55:42Z DEBUG 5 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-logrotationtimeunit: 2022-12-17T23:55:42Z DEBUG week 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog: 2022-12-17T23:55:42Z DEBUG /var/log/dirsrv/slapd-REDACTED_DOMAIN-COM/security 2022-12-17T23:55:42Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-extract-pemfiles: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-logging-backend: 2022-12-17T23:55:42Z DEBUG dirsrv-log 2022-12-17T23:55:42Z DEBUG nsslapd-tls-check-crl: 2022-12-17T23:55:42Z DEBUG none 2022-12-17T23:55:42Z DEBUG nsslapd-enable-upgrade-hash: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-verify-filter-schema: 2022-12-17T23:55:42Z DEBUG process-safe 2022-12-17T23:55:42Z DEBUG nsslapd-enable-ldapssotoken: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-ldapssotoken-ttl-secs: 2022-12-17T23:55:42Z DEBUG 3600 2022-12-17T23:55:42Z DEBUG nsslapd-tcp-fin-timeout: 2022-12-17T23:55:42Z DEBUG 30 2022-12-17T23:55:42Z DEBUG nsslapd-tcp-keepalive-time: 2022-12-17T23:55:42Z DEBUG 300 2022-12-17T23:55:42Z DEBUG nsslapd-return-original-entrydn: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG passwordStorageScheme: 2022-12-17T23:55:42Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:42Z DEBUG passwordAdminDN: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-rootpwstoragescheme: 2022-12-17T23:55:42Z DEBUG PBKDF2-SHA512 2022-12-17T23:55:42Z DEBUG nsslapd-errorlog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-accesslog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-auditlog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ssl-check-hostname: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-hash-filters: 2022-12-17T23:55:42Z DEBUG off 2022-12-17T23:55:42Z DEBUG nsslapd-auditfaillog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-securitylog-list: 2022-12-17T23:55:42Z DEBUG 2022-12-17T23:55:42Z DEBUG nsslapd-ldapssotoken-secret: 2022-12-17T23:55:42Z DEBUG BdBvsyH_35c-L2qd4NirFR37JswUZOY2dsMj0cyjGcw= 2022-12-17T23:55:42Z DEBUG aci: 2022-12-17T23:55:42Z DEBUG (targetattr != "aci")(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2022-12-17T23:55:42Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr = "*")(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || objectclass || nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Read Replication Changelog Configuration"; allow (read,search) groupdn = "ldap:///cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "nsslapd-changelogmaxentries || nsslapd-changelogmaxage || nsslapd-changelogtrim-interval || nsslapd-encryptionalgorithm || nsSymmetricKey")(targetfilter = "cn=changelog")(target = "ldap:///cn=ldbm database,cn=plugins,cn=config")(version 3.0; acl "permission:Write Replication Changelog Configuration"; allow (write) groupdn = "ldap:///cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:42Z DEBUG [(0, 'aci', ['(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:42Z DEBUG Updated 1 2022-12-17T23:55:42Z DEBUG update_entry modlist [(0, 'aci', [b'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:42Z DEBUG Done 2022-12-17T23:55:42Z DEBUG New entry: cn=CA Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=CA Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG nestedgroup 2022-12-17T23:55:42Z DEBUG groupofnames 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG CA Administrator 2022-12-17T23:55:42Z DEBUG description: 2022-12-17T23:55:42Z DEBUG CA Administrator 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=CA Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG nestedgroup 2022-12-17T23:55:42Z DEBUG groupofnames 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG CA Administrator 2022-12-17T23:55:42Z DEBUG description: 2022-12-17T23:55:42Z DEBUG CA Administrator 2022-12-17T23:55:42Z DEBUG New entry: cn=Vault Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=Vault Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG nestedgroup 2022-12-17T23:55:42Z DEBUG groupofnames 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG Vault Administrators 2022-12-17T23:55:42Z DEBUG description: 2022-12-17T23:55:42Z DEBUG Vault Administrators 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=Vault Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG nestedgroup 2022-12-17T23:55:42Z DEBUG groupofnames 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG Vault Administrators 2022-12-17T23:55:42Z DEBUG description: 2022-12-17T23:55:42Z DEBUG Vault Administrators 2022-12-17T23:55:42Z DEBUG Updating existing entry: cn=DNS Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=DNS Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG groupofnames 2022-12-17T23:55:42Z DEBUG nestedgroup 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG DNS Administrators 2022-12-17T23:55:42Z DEBUG description: 2022-12-17T23:55:42Z DEBUG DNS Administrators 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=DNS Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG groupofnames 2022-12-17T23:55:42Z DEBUG nestedgroup 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG DNS Administrators 2022-12-17T23:55:42Z DEBUG description: 2022-12-17T23:55:42Z DEBUG DNS Administrators 2022-12-17T23:55:42Z DEBUG [] 2022-12-17T23:55:42Z DEBUG Updated 0 2022-12-17T23:55:42Z DEBUG Done 2022-12-17T23:55:42Z DEBUG Updating existing entry: cn=DNS Servers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=DNS Servers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG groupofnames 2022-12-17T23:55:42Z DEBUG nestedgroup 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG DNS Servers 2022-12-17T23:55:42Z DEBUG description: 2022-12-17T23:55:42Z DEBUG DNS Servers 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=DNS Servers,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG groupofnames 2022-12-17T23:55:42Z DEBUG nestedgroup 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG DNS Servers 2022-12-17T23:55:42Z DEBUG description: 2022-12-17T23:55:42Z DEBUG DNS Servers 2022-12-17T23:55:42Z DEBUG [] 2022-12-17T23:55:42Z DEBUG Updated 0 2022-12-17T23:55:42Z DEBUG Done 2022-12-17T23:55:42Z DEBUG Updating existing entry: cn=External IdP server Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=External IdP server Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG groupofnames 2022-12-17T23:55:42Z DEBUG nestedgroup 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG External IdP server Administrators 2022-12-17T23:55:42Z DEBUG description: 2022-12-17T23:55:42Z DEBUG External IdP server Administrators 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=External IdP server Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG groupofnames 2022-12-17T23:55:42Z DEBUG nestedgroup 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG External IdP server Administrators 2022-12-17T23:55:42Z DEBUG description: 2022-12-17T23:55:42Z DEBUG External IdP server Administrators 2022-12-17T23:55:42Z DEBUG [] 2022-12-17T23:55:42Z DEBUG Updated 0 2022-12-17T23:55:42Z DEBUG Done 2022-12-17T23:55:42Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-delegation.update 1.230 sec 2022-12-17T23:55:42Z DEBUG Parsing update file '/usr/share/ipa/updates/40-dns.update' 2022-12-17T23:55:42Z DEBUG New entry: cn=dns,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=dns,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG addifexist: 'idnsConfigObject' to objectClass, current value [] 2022-12-17T23:55:42Z DEBUG addifexist: '(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)' to aci, current value [] 2022-12-17T23:55:42Z DEBUG addifexist: '(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)' to aci, current value [] 2022-12-17T23:55:42Z DEBUG addifexist: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' to aci, current value [] 2022-12-17T23:55:42Z DEBUG addifexist: '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value [] 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=dns,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG New entry: cn=dns,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=dns,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG replace: (targetattr = "*")(version 3.0; acl "No access to DNS tree without a permission"; deny (read,search,compare) (groupdn != "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com") and (groupdn != "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com");) not found, skipping 2022-12-17T23:55:42Z DEBUG replace: (targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com" or userattr = "parent[0,1].managedby#GROUPDN";) not found, skipping 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=dns,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG New entry: cn=dns,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=dns,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2022-12-17T23:55:42Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2022-12-17T23:55:42Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord ")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2022-12-17T23:55:42Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord ")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2022-12-17T23:55:42Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2022-12-17T23:55:42Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2022-12-17T23:55:42Z DEBUG remove: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2022-12-17T23:55:42Z DEBUG remove: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=dns,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG Updating existing entry: cn=IPA DNS,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=IPA DNS,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG IPA DNS 2022-12-17T23:55:42Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:42Z DEBUG database 2022-12-17T23:55:42Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:42Z DEBUG IPA DNS support plugin 2022-12-17T23:55:42Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:42Z DEBUG ipa_dns 2022-12-17T23:55:42Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:42Z DEBUG ipadns_init 2022-12-17T23:55:42Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:42Z DEBUG libipa_dns.so 2022-12-17T23:55:42Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:42Z DEBUG preoperation 2022-12-17T23:55:42Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:42Z DEBUG Red Hat, Inc. 2022-12-17T23:55:42Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:42Z DEBUG 1.0 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG nsslapdPlugin 2022-12-17T23:55:42Z DEBUG extensibleObject 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=IPA DNS,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG IPA DNS 2022-12-17T23:55:42Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:42Z DEBUG database 2022-12-17T23:55:42Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:42Z DEBUG IPA DNS support plugin 2022-12-17T23:55:42Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:42Z DEBUG on 2022-12-17T23:55:42Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:42Z DEBUG ipa_dns 2022-12-17T23:55:42Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:42Z DEBUG ipadns_init 2022-12-17T23:55:42Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:42Z DEBUG libipa_dns.so 2022-12-17T23:55:42Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:42Z DEBUG preoperation 2022-12-17T23:55:42Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:42Z DEBUG Red Hat, Inc. 2022-12-17T23:55:42Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:42Z DEBUG 1.0 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG nsslapdPlugin 2022-12-17T23:55:42Z DEBUG extensibleObject 2022-12-17T23:55:42Z DEBUG [] 2022-12-17T23:55:42Z DEBUG Updated 0 2022-12-17T23:55:42Z DEBUG Done 2022-12-17T23:55:42Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-dns.update 0.009 sec 2022-12-17T23:55:42Z DEBUG Parsing update file '/usr/share/ipa/updates/40-idp.update' 2022-12-17T23:55:42Z DEBUG New entry: cn=idp,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=idp,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG nsContainer 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG idp 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=idp,dc=redacted_domain,dc=com 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG nsContainer 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG idp 2022-12-17T23:55:42Z DEBUG New entry: cn=ipaidpconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Initial value 2022-12-17T23:55:42Z DEBUG dn: cn=ipaidpconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG nsIndex 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG nsSystemIndex: 2022-12-17T23:55:42Z DEBUG false 2022-12-17T23:55:42Z DEBUG only: set cn to 'ipaidpconfiglink', current value [] 2022-12-17T23:55:42Z DEBUG only: updated value ['ipaidpconfiglink'] 2022-12-17T23:55:42Z DEBUG add: 'eq' to nsIndexType, current value [] 2022-12-17T23:55:42Z DEBUG add: updated value ['eq'] 2022-12-17T23:55:42Z DEBUG add: 'pres' to nsIndexType, current value ['eq'] 2022-12-17T23:55:42Z DEBUG add: updated value ['eq', 'pres'] 2022-12-17T23:55:42Z DEBUG add: 'sub' to nsIndexType, current value ['eq', 'pres'] 2022-12-17T23:55:42Z DEBUG add: updated value ['eq', 'pres', 'sub'] 2022-12-17T23:55:42Z DEBUG --------------------------------------------- 2022-12-17T23:55:42Z DEBUG Final value after applying updates 2022-12-17T23:55:42Z DEBUG dn: cn=ipaidpconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:42Z DEBUG objectClass: 2022-12-17T23:55:42Z DEBUG nsIndex 2022-12-17T23:55:42Z DEBUG top 2022-12-17T23:55:42Z DEBUG nsSystemIndex: 2022-12-17T23:55:42Z DEBUG false 2022-12-17T23:55:42Z DEBUG cn: 2022-12-17T23:55:42Z DEBUG ipaidpconfiglink 2022-12-17T23:55:42Z DEBUG nsIndexType: 2022-12-17T23:55:42Z DEBUG eq 2022-12-17T23:55:42Z DEBUG pres 2022-12-17T23:55:42Z DEBUG sub 2022-12-17T23:55:42Z DEBUG Creating task cn=indextask_138906141425013830_15022,cn=index,cn=tasks,cn=config to index attributes: ipaidpconfiglink 2022-12-17T23:55:43Z DEBUG Indexing finished 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-idp.update 1.025 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/40-otp.update' 2022-12-17T23:55:43Z DEBUG New entry: cn=otp,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=otp,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nsContainer 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG otp 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=otp,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nsContainer 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG otp 2022-12-17T23:55:43Z DEBUG New entry: cn=otp,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=otp,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG ipatokenOTPConfig 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG otp 2022-12-17T23:55:43Z DEBUG ipatokenTOTPauthWindow: 2022-12-17T23:55:43Z DEBUG 300 2022-12-17T23:55:43Z DEBUG ipatokenTOTPsyncWindow: 2022-12-17T23:55:43Z DEBUG 86400 2022-12-17T23:55:43Z DEBUG ipatokenHOTPauthWindow: 2022-12-17T23:55:43Z DEBUG 10 2022-12-17T23:55:43Z DEBUG ipatokenHOTPsyncWindow: 2022-12-17T23:55:43Z DEBUG 100 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=otp,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG ipatokenOTPConfig 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG otp 2022-12-17T23:55:43Z DEBUG ipatokenTOTPauthWindow: 2022-12-17T23:55:43Z DEBUG 300 2022-12-17T23:55:43Z DEBUG ipatokenTOTPsyncWindow: 2022-12-17T23:55:43Z DEBUG 86400 2022-12-17T23:55:43Z DEBUG ipatokenHOTPauthWindow: 2022-12-17T23:55:43Z DEBUG 10 2022-12-17T23:55:43Z DEBUG ipatokenHOTPsyncWindow: 2022-12-17T23:55:43Z DEBUG 100 2022-12-17T23:55:43Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG domain 2022-12-17T23:55:43Z DEBUG pilotObject 2022-12-17T23:55:43Z DEBUG domainRelatedObject 2022-12-17T23:55:43Z DEBUG nisDomainObject 2022-12-17T23:55:43Z DEBUG dc: 2022-12-17T23:55:43Z DEBUG redacted_domain 2022-12-17T23:55:43Z DEBUG info: 2022-12-17T23:55:43Z DEBUG IPA V2.0 2022-12-17T23:55:43Z DEBUG associatedDomain: 2022-12-17T23:55:43Z DEBUG redacted_domain.com 2022-12-17T23:55:43Z DEBUG nisDomain: 2022-12-17T23:55:43Z DEBUG redacted_domain.com 2022-12-17T23:55:43Z DEBUG aci: 2022-12-17T23:55:43Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:43Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:43Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:43Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:43Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:43Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:43Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:43Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:43Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:43Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:43Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:43Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:43Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:43Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:43Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG remove: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG remove: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' not in aci 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' not in aci 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' not in aci 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' not in aci 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenHOTPcounter")(version 3.0; acl "Users can add HOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenHOTPcounter")(version 3.0; acl "Users can add HOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' not in aci 2022-12-17T23:55:43Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2022-12-17T23:55:43Z DEBUG add: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2022-12-17T23:55:43Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2022-12-17T23:55:43Z DEBUG add: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2022-12-17T23:55:43Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2022-12-17T23:55:43Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2022-12-17T23:55:43Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)'] 2022-12-17T23:55:43Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)'] 2022-12-17T23:55:43Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)'] 2022-12-17T23:55:43Z DEBUG add: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)'] 2022-12-17T23:55:43Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG domain 2022-12-17T23:55:43Z DEBUG pilotObject 2022-12-17T23:55:43Z DEBUG domainRelatedObject 2022-12-17T23:55:43Z DEBUG nisDomainObject 2022-12-17T23:55:43Z DEBUG dc: 2022-12-17T23:55:43Z DEBUG redacted_domain 2022-12-17T23:55:43Z DEBUG info: 2022-12-17T23:55:43Z DEBUG IPA V2.0 2022-12-17T23:55:43Z DEBUG associatedDomain: 2022-12-17T23:55:43Z DEBUG redacted_domain.com 2022-12-17T23:55:43Z DEBUG nisDomain: 2022-12-17T23:55:43Z DEBUG redacted_domain.com 2022-12-17T23:55:43Z DEBUG aci: 2022-12-17T23:55:43Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:43Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:43Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:43Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:43Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:43Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:43Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:43Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:43Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:43Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:43Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:43Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:43Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:43Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:43Z DEBUG [] 2022-12-17T23:55:43Z DEBUG Updated 0 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG New entry: cn=radiusproxy,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=radiusproxy,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nsContainer 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG radiusproxy 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=radiusproxy,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nsContainer 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG radiusproxy 2022-12-17T23:55:43Z DEBUG New entry: cn=IPA OTP Last Token,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=IPA OTP Last Token,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG objectclass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG nsSlapdPlugin 2022-12-17T23:55:43Z DEBUG extensibleObject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG IPA OTP Last Token 2022-12-17T23:55:43Z DEBUG nsslapd-pluginpath: 2022-12-17T23:55:43Z DEBUG libipa_otp_lasttoken 2022-12-17T23:55:43Z DEBUG nsslapd-plugininitfunc: 2022-12-17T23:55:43Z DEBUG ipa_otp_lasttoken_init 2022-12-17T23:55:43Z DEBUG nsslapd-plugintype: 2022-12-17T23:55:43Z DEBUG preoperation 2022-12-17T23:55:43Z DEBUG nsslapd-pluginenabled: 2022-12-17T23:55:43Z DEBUG on 2022-12-17T23:55:43Z DEBUG nsslapd-pluginid: 2022-12-17T23:55:43Z DEBUG ipa-otp-lasttoken 2022-12-17T23:55:43Z DEBUG nsslapd-pluginversion: 2022-12-17T23:55:43Z DEBUG 1.0 2022-12-17T23:55:43Z DEBUG nsslapd-pluginvendor: 2022-12-17T23:55:43Z DEBUG Red Hat, Inc. 2022-12-17T23:55:43Z DEBUG nsslapd-plugindescription: 2022-12-17T23:55:43Z DEBUG IPA OTP Last Token plugin 2022-12-17T23:55:43Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:43Z DEBUG database 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=IPA OTP Last Token,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG objectclass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG nsSlapdPlugin 2022-12-17T23:55:43Z DEBUG extensibleObject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG IPA OTP Last Token 2022-12-17T23:55:43Z DEBUG nsslapd-pluginpath: 2022-12-17T23:55:43Z DEBUG libipa_otp_lasttoken 2022-12-17T23:55:43Z DEBUG nsslapd-plugininitfunc: 2022-12-17T23:55:43Z DEBUG ipa_otp_lasttoken_init 2022-12-17T23:55:43Z DEBUG nsslapd-plugintype: 2022-12-17T23:55:43Z DEBUG preoperation 2022-12-17T23:55:43Z DEBUG nsslapd-pluginenabled: 2022-12-17T23:55:43Z DEBUG on 2022-12-17T23:55:43Z DEBUG nsslapd-pluginid: 2022-12-17T23:55:43Z DEBUG ipa-otp-lasttoken 2022-12-17T23:55:43Z DEBUG nsslapd-pluginversion: 2022-12-17T23:55:43Z DEBUG 1.0 2022-12-17T23:55:43Z DEBUG nsslapd-pluginvendor: 2022-12-17T23:55:43Z DEBUG Red Hat, Inc. 2022-12-17T23:55:43Z DEBUG nsslapd-plugindescription: 2022-12-17T23:55:43Z DEBUG IPA OTP Last Token plugin 2022-12-17T23:55:43Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:43Z DEBUG database 2022-12-17T23:55:43Z DEBUG New entry: cn=IPA OTP Counter,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=IPA OTP Counter,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG objectclass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG nsSlapdPlugin 2022-12-17T23:55:43Z DEBUG extensibleObject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG IPA OTP Counter 2022-12-17T23:55:43Z DEBUG nsslapd-pluginpath: 2022-12-17T23:55:43Z DEBUG libipa_otp_counter 2022-12-17T23:55:43Z DEBUG nsslapd-plugininitfunc: 2022-12-17T23:55:43Z DEBUG ipa_otp_counter_init 2022-12-17T23:55:43Z DEBUG nsslapd-plugintype: 2022-12-17T23:55:43Z DEBUG preoperation 2022-12-17T23:55:43Z DEBUG nsslapd-pluginenabled: 2022-12-17T23:55:43Z DEBUG on 2022-12-17T23:55:43Z DEBUG nsslapd-pluginid: 2022-12-17T23:55:43Z DEBUG ipa-otp-counter 2022-12-17T23:55:43Z DEBUG nsslapd-pluginversion: 2022-12-17T23:55:43Z DEBUG 1.0 2022-12-17T23:55:43Z DEBUG nsslapd-pluginvendor: 2022-12-17T23:55:43Z DEBUG Red Hat, Inc. 2022-12-17T23:55:43Z DEBUG nsslapd-plugindescription: 2022-12-17T23:55:43Z DEBUG IPA OTP Counter plugin 2022-12-17T23:55:43Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:43Z DEBUG database 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=IPA OTP Counter,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG objectclass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG nsSlapdPlugin 2022-12-17T23:55:43Z DEBUG extensibleObject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG IPA OTP Counter 2022-12-17T23:55:43Z DEBUG nsslapd-pluginpath: 2022-12-17T23:55:43Z DEBUG libipa_otp_counter 2022-12-17T23:55:43Z DEBUG nsslapd-plugininitfunc: 2022-12-17T23:55:43Z DEBUG ipa_otp_counter_init 2022-12-17T23:55:43Z DEBUG nsslapd-plugintype: 2022-12-17T23:55:43Z DEBUG preoperation 2022-12-17T23:55:43Z DEBUG nsslapd-pluginenabled: 2022-12-17T23:55:43Z DEBUG on 2022-12-17T23:55:43Z DEBUG nsslapd-pluginid: 2022-12-17T23:55:43Z DEBUG ipa-otp-counter 2022-12-17T23:55:43Z DEBUG nsslapd-pluginversion: 2022-12-17T23:55:43Z DEBUG 1.0 2022-12-17T23:55:43Z DEBUG nsslapd-pluginvendor: 2022-12-17T23:55:43Z DEBUG Red Hat, Inc. 2022-12-17T23:55:43Z DEBUG nsslapd-plugindescription: 2022-12-17T23:55:43Z DEBUG IPA OTP Counter plugin 2022-12-17T23:55:43Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:43Z DEBUG database 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-otp.update 0.050 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/40-realm_domains.update' 2022-12-17T23:55:43Z DEBUG New entry: cn=Realm Domains,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Realm Domains,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG domainRelatedObject 2022-12-17T23:55:43Z DEBUG nsContainer 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Realm Domains 2022-12-17T23:55:43Z DEBUG associatedDomain: 2022-12-17T23:55:43Z DEBUG redacted_domain.com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Realm Domains,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG domainRelatedObject 2022-12-17T23:55:43Z DEBUG nsContainer 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Realm Domains 2022-12-17T23:55:43Z DEBUG associatedDomain: 2022-12-17T23:55:43Z DEBUG redacted_domain.com 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-realm_domains.update 0.005 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/40-replication.update' 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG userRoot 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG extensibleObject 2022-12-17T23:55:43Z DEBUG nsBackendInstance 2022-12-17T23:55:43Z DEBUG nsslapd-suffix: 2022-12-17T23:55:43Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG nsslapd-cachesize: 2022-12-17T23:55:43Z DEBUG -1 2022-12-17T23:55:43Z DEBUG nsslapd-cachememsize: 2022-12-17T23:55:43Z DEBUG 738197504 2022-12-17T23:55:43Z DEBUG nsslapd-readonly: 2022-12-17T23:55:43Z DEBUG off 2022-12-17T23:55:43Z DEBUG nsslapd-require-index: 2022-12-17T23:55:43Z DEBUG off 2022-12-17T23:55:43Z DEBUG nsslapd-require-internalop-index: 2022-12-17T23:55:43Z DEBUG off 2022-12-17T23:55:43Z DEBUG nsslapd-dncachememsize: 2022-12-17T23:55:43Z DEBUG 134217728 2022-12-17T23:55:43Z DEBUG nsslapd-directory: 2022-12-17T23:55:43Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/db/userRoot 2022-12-17T23:55:43Z DEBUG aci: 2022-12-17T23:55:43Z DEBUG (targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG remove: '(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG remove: '(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:43Z DEBUG add: '(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG add: updated value ['(targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG userRoot 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG extensibleObject 2022-12-17T23:55:43Z DEBUG nsBackendInstance 2022-12-17T23:55:43Z DEBUG nsslapd-suffix: 2022-12-17T23:55:43Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG nsslapd-cachesize: 2022-12-17T23:55:43Z DEBUG -1 2022-12-17T23:55:43Z DEBUG nsslapd-cachememsize: 2022-12-17T23:55:43Z DEBUG 738197504 2022-12-17T23:55:43Z DEBUG nsslapd-readonly: 2022-12-17T23:55:43Z DEBUG off 2022-12-17T23:55:43Z DEBUG nsslapd-require-index: 2022-12-17T23:55:43Z DEBUG off 2022-12-17T23:55:43Z DEBUG nsslapd-require-internalop-index: 2022-12-17T23:55:43Z DEBUG off 2022-12-17T23:55:43Z DEBUG nsslapd-dncachememsize: 2022-12-17T23:55:43Z DEBUG 134217728 2022-12-17T23:55:43Z DEBUG nsslapd-directory: 2022-12-17T23:55:43Z DEBUG /var/lib/dirsrv/slapd-REDACTED_DOMAIN-COM/db/userRoot 2022-12-17T23:55:43Z DEBUG aci: 2022-12-17T23:55:43Z DEBUG (targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG [] 2022-12-17T23:55:43Z DEBUG Updated 0 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG ipapermission 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Modify DNA Range 2022-12-17T23:55:43Z DEBUG ipaPermissionType: 2022-12-17T23:55:43Z DEBUG SYSTEM 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG ipapermission 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Modify DNA Range 2022-12-17T23:55:43Z DEBUG ipaPermissionType: 2022-12-17T23:55:43Z DEBUG SYSTEM 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [] 2022-12-17T23:55:43Z DEBUG Updated 0 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Posix IDs 2022-12-17T23:55:43Z DEBUG dnaExcludeScope: 2022-12-17T23:55:43Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG dnaFilter: 2022-12-17T23:55:43Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2022-12-17T23:55:43Z DEBUG dnaMagicRegen: 2022-12-17T23:55:43Z DEBUG -1 2022-12-17T23:55:43Z DEBUG dnaMaxValue: 2022-12-17T23:55:43Z DEBUG 1382999999 2022-12-17T23:55:43Z DEBUG dnaNextValue: 2022-12-17T23:55:43Z DEBUG 1382800000 2022-12-17T23:55:43Z DEBUG dnaScope: 2022-12-17T23:55:43Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG dnaSharedCfgDN: 2022-12-17T23:55:43Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG dnaThreshold: 2022-12-17T23:55:43Z DEBUG 500 2022-12-17T23:55:43Z DEBUG dnaType: 2022-12-17T23:55:43Z DEBUG uidNumber 2022-12-17T23:55:43Z DEBUG gidNumber 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG extensibleObject 2022-12-17T23:55:43Z DEBUG aci: 2022-12-17T23:55:43Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG remove: '(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG remove: '(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:43Z DEBUG add: '(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG add: updated value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Posix IDs 2022-12-17T23:55:43Z DEBUG dnaExcludeScope: 2022-12-17T23:55:43Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG dnaFilter: 2022-12-17T23:55:43Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2022-12-17T23:55:43Z DEBUG dnaMagicRegen: 2022-12-17T23:55:43Z DEBUG -1 2022-12-17T23:55:43Z DEBUG dnaMaxValue: 2022-12-17T23:55:43Z DEBUG 1382999999 2022-12-17T23:55:43Z DEBUG dnaNextValue: 2022-12-17T23:55:43Z DEBUG 1382800000 2022-12-17T23:55:43Z DEBUG dnaScope: 2022-12-17T23:55:43Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG dnaSharedCfgDN: 2022-12-17T23:55:43Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG dnaThreshold: 2022-12-17T23:55:43Z DEBUG 500 2022-12-17T23:55:43Z DEBUG dnaType: 2022-12-17T23:55:43Z DEBUG uidNumber 2022-12-17T23:55:43Z DEBUG gidNumber 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG extensibleObject 2022-12-17T23:55:43Z DEBUG aci: 2022-12-17T23:55:43Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG [] 2022-12-17T23:55:43Z DEBUG Updated 0 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG New entry: cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG ipapermission 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Read DNA Range 2022-12-17T23:55:43Z DEBUG ipapermissiontype: 2022-12-17T23:55:43Z DEBUG SYSTEM 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG ipapermission 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Read DNA Range 2022-12-17T23:55:43Z DEBUG ipapermissiontype: 2022-12-17T23:55:43Z DEBUG SYSTEM 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Posix IDs 2022-12-17T23:55:43Z DEBUG dnaExcludeScope: 2022-12-17T23:55:43Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG dnaFilter: 2022-12-17T23:55:43Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2022-12-17T23:55:43Z DEBUG dnaMagicRegen: 2022-12-17T23:55:43Z DEBUG -1 2022-12-17T23:55:43Z DEBUG dnaMaxValue: 2022-12-17T23:55:43Z DEBUG 1382999999 2022-12-17T23:55:43Z DEBUG dnaNextValue: 2022-12-17T23:55:43Z DEBUG 1382800000 2022-12-17T23:55:43Z DEBUG dnaScope: 2022-12-17T23:55:43Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG dnaSharedCfgDN: 2022-12-17T23:55:43Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG dnaThreshold: 2022-12-17T23:55:43Z DEBUG 500 2022-12-17T23:55:43Z DEBUG dnaType: 2022-12-17T23:55:43Z DEBUG uidNumber 2022-12-17T23:55:43Z DEBUG gidNumber 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG extensibleObject 2022-12-17T23:55:43Z DEBUG aci: 2022-12-17T23:55:43Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG remove: '(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG remove: '(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:43Z DEBUG add: '(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG add: updated value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Posix IDs 2022-12-17T23:55:43Z DEBUG dnaExcludeScope: 2022-12-17T23:55:43Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG dnaFilter: 2022-12-17T23:55:43Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2022-12-17T23:55:43Z DEBUG dnaMagicRegen: 2022-12-17T23:55:43Z DEBUG -1 2022-12-17T23:55:43Z DEBUG dnaMaxValue: 2022-12-17T23:55:43Z DEBUG 1382999999 2022-12-17T23:55:43Z DEBUG dnaNextValue: 2022-12-17T23:55:43Z DEBUG 1382800000 2022-12-17T23:55:43Z DEBUG dnaScope: 2022-12-17T23:55:43Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG dnaSharedCfgDN: 2022-12-17T23:55:43Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG dnaThreshold: 2022-12-17T23:55:43Z DEBUG 500 2022-12-17T23:55:43Z DEBUG dnaType: 2022-12-17T23:55:43Z DEBUG uidNumber 2022-12-17T23:55:43Z DEBUG gidNumber 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG extensibleObject 2022-12-17T23:55:43Z DEBUG aci: 2022-12-17T23:55:43Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG (targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:43Z DEBUG [(0, 'aci', ['(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-replication.update 0.073 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/40-vault.update' 2022-12-17T23:55:43Z DEBUG New entry: cn=vaults,cn=kra,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=vaults,cn=kra,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value [] 2022-12-17T23:55:43Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:43Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value [] 2022-12-17T23:55:43Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' from aci, current value [] 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' not in aci 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' from aci, current value [] 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' not in aci 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' from aci, current value [] 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' not in aci 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' from aci, current value [] 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' not in aci 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' from aci, current value [] 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' not in aci 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' from aci, current value [] 2022-12-17T23:55:43Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' not in aci 2022-12-17T23:55:43Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)' from aci, current value [] 2022-12-17T23:55:43Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)' not in aci 2022-12-17T23:55:43Z DEBUG addifexist: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)' to aci, current value [] 2022-12-17T23:55:43Z DEBUG addifexist: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)' to aci, current value [] 2022-12-17T23:55:43Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value [] 2022-12-17T23:55:43Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value [] 2022-12-17T23:55:43Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value [] 2022-12-17T23:55:43Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value [] 2022-12-17T23:55:43Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)' to aci, current value [] 2022-12-17T23:55:43Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)' to aci, current value [] 2022-12-17T23:55:43Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value [] 2022-12-17T23:55:43Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value [] 2022-12-17T23:55:43Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' to aci, current value [] 2022-12-17T23:55:43Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' to aci, current value [] 2022-12-17T23:55:43Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Vault owners can manage the vault"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value [] 2022-12-17T23:55:43Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value [] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=vaults,cn=kra,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-vault.update 0.005 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/41-caacl.update' 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=caacls,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=caacls,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nsContainer 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG caacls 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=caacls,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nsContainer 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG caacls 2022-12-17T23:55:43Z DEBUG [] 2022-12-17T23:55:43Z DEBUG Updated 0 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/41-caacl.update 0.002 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/41-lightweight-cas.update' 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=cas,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=cas,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nsContainer 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG cas 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=cas,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nsContainer 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG cas 2022-12-17T23:55:43Z DEBUG [] 2022-12-17T23:55:43Z DEBUG Updated 0 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/41-lightweight-cas.update 0.002 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/45-roles.update' 2022-12-17T23:55:43Z DEBUG New entry: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Modify Users and Reset passwords 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Modify Users and Reset passwords 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Modify Users and Reset passwords 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Modify Users and Reset passwords 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG New entry: cn=Modify Group membership,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Modify Group membership,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Modify Group membership 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Modify Group membership 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Modify Group membership,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Modify Group membership 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Modify Group membership 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG New entry: cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG User Administrator 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Responsible for creating Users and Groups 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG User Administrator 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Responsible for creating Users and Groups 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=User Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=User Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG User Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG User Administrators 2022-12-17T23:55:43Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=User Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG User Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG User Administrators 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(2, 'member', ['cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(2, 'member', [b'cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Group Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Group Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Group Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Group Administrators 2022-12-17T23:55:43Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Group Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Group Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Group Administrators 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(2, 'member', ['cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(2, 'member', [b'cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Stage User Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Stage User Administrators 2022-12-17T23:55:43Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Stage User Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Stage User Administrators 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(2, 'member', ['cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(2, 'member', [b'cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG New entry: cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG IT Specialist 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG IT Specialist 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG IT Specialist 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG IT Specialist 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Host Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Host Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Host Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Host Administrators 2022-12-17T23:55:43Z DEBUG memberOf: 2022-12-17T23:55:43Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Host Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Host Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Host Administrators 2022-12-17T23:55:43Z DEBUG memberOf: 2022-12-17T23:55:43Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(2, 'member', ['cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(2, 'member', [b'cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Host Group Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Host Group Administrators 2022-12-17T23:55:43Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Host Group Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Host Group Administrators 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(2, 'member', ['cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(2, 'member', [b'cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Service Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Service Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Service Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Service Administrators 2022-12-17T23:55:43Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Service Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Service Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Service Administrators 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(2, 'member', ['cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(2, 'member', [b'cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Automount Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Automount Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Automount Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Automount Administrators 2022-12-17T23:55:43Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Automount Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Automount Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Automount Administrators 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(2, 'member', ['cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(2, 'member', [b'cn=IT Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG New entry: cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG IT Security Specialist 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG IT Security Specialist 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG IT Security Specialist 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG IT Security Specialist 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Netgroups Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Netgroups Administrators 2022-12-17T23:55:43Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Netgroups Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Netgroups Administrators 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(2, 'member', ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(2, 'member', [b'cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG HBAC Administrator 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG HBAC Administrator 2022-12-17T23:55:43Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG HBAC Administrator 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG HBAC Administrator 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(2, 'member', ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(2, 'member', [b'cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Sudo Administrator 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Sudo Administrator 2022-12-17T23:55:43Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Sudo Administrator 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Sudo Administrator 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(2, 'member', ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(2, 'member', [b'cn=IT Security Specialist,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG New entry: cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Security Architect 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Security Architect 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Security Architect 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Security Architect 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Delegation Administrator 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Role administration 2022-12-17T23:55:43Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Delegation Administrator 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Role administration 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(2, 'member', ['cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(2, 'member', [b'cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Replication Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Replication Administrators 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG memberOf: 2022-12-17T23:55:43Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG add: 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com' to member, current value ['cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value ['cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com', 'cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Replication Administrators 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Replication Administrators 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG memberOf: 2022-12-17T23:55:43Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(0, 'member', ['cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com', 'cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(0, 'member', [b'cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com', b'cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Write IPA Configuration 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Write IPA Configuration 2022-12-17T23:55:43Z DEBUG memberOf: 2022-12-17T23:55:43Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Write IPA Configuration 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Write IPA Configuration 2022-12-17T23:55:43Z DEBUG memberOf: 2022-12-17T23:55:43Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(2, 'member', ['cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(2, 'member', [b'cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Password Policy Administrator 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Password Policy Administrator 2022-12-17T23:55:43Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Password Policy Administrator 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Password Policy Administrator 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(2, 'member', ['cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(2, 'member', [b'cn=Security Architect,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG New entry: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Enrollment Administrator 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Enrollment Administrator responsible for client(host) enrollment 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Enrollment Administrator 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Enrollment Administrator responsible for client(host) enrollment 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=Host Enrollment,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Host Enrollment 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Host Enrollment 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG add: 'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com' to member, current value ['cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com', 'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG Host Enrollment 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Host Enrollment 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Enrollment Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [(0, 'member', ['cn=Enrollment Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(0, 'member', [b'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/45-roles.update 0.239 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/49-autobind-services.update' 2022-12-17T23:55:43Z DEBUG New entry: cn=named,cn=auto_bind,cn=config 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=named,cn=auto_bind,cn=config 2022-12-17T23:55:43Z DEBUG onlyifexist: '25' to uidNumber, current value [] 2022-12-17T23:55:43Z DEBUG onlyifexist: '25' to gidNumber, current value [] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=named,cn=auto_bind,cn=config 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/49-autobind-services.update 0.002 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/50-7_bit_check.update' 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG 7-bit check 2022-12-17T23:55:43Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:43Z DEBUG database 2022-12-17T23:55:43Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:43Z DEBUG Enforce 7-bit clean attribute values 2022-12-17T23:55:43Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:43Z DEBUG on 2022-12-17T23:55:43Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:43Z DEBUG NS7bitAttr 2022-12-17T23:55:43Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:43Z DEBUG NS7bitAttr_Init 2022-12-17T23:55:43Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:43Z DEBUG libattr-unique-plugin 2022-12-17T23:55:43Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:43Z DEBUG betxnpreoperation 2022-12-17T23:55:43Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:43Z DEBUG 389 Project 2022-12-17T23:55:43Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:43Z DEBUG 2.2.4 2022-12-17T23:55:43Z DEBUG nsslapd-pluginarg0: 2022-12-17T23:55:43Z DEBUG uid 2022-12-17T23:55:43Z DEBUG nsslapd-pluginarg1: 2022-12-17T23:55:43Z DEBUG mail 2022-12-17T23:55:43Z DEBUG nsslapd-pluginarg2: 2022-12-17T23:55:43Z DEBUG , 2022-12-17T23:55:43Z DEBUG nsslapd-pluginarg3: 2022-12-17T23:55:43Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG nsSlapdPlugin 2022-12-17T23:55:43Z DEBUG extensibleObject 2022-12-17T23:55:43Z DEBUG replace: userpassword not found, skipping 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG 7-bit check 2022-12-17T23:55:43Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:43Z DEBUG database 2022-12-17T23:55:43Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:43Z DEBUG Enforce 7-bit clean attribute values 2022-12-17T23:55:43Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:43Z DEBUG on 2022-12-17T23:55:43Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:43Z DEBUG NS7bitAttr 2022-12-17T23:55:43Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:43Z DEBUG NS7bitAttr_Init 2022-12-17T23:55:43Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:43Z DEBUG libattr-unique-plugin 2022-12-17T23:55:43Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:43Z DEBUG betxnpreoperation 2022-12-17T23:55:43Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:43Z DEBUG 389 Project 2022-12-17T23:55:43Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:43Z DEBUG 2.2.4 2022-12-17T23:55:43Z DEBUG nsslapd-pluginarg0: 2022-12-17T23:55:43Z DEBUG uid 2022-12-17T23:55:43Z DEBUG nsslapd-pluginarg1: 2022-12-17T23:55:43Z DEBUG mail 2022-12-17T23:55:43Z DEBUG nsslapd-pluginarg2: 2022-12-17T23:55:43Z DEBUG , 2022-12-17T23:55:43Z DEBUG nsslapd-pluginarg3: 2022-12-17T23:55:43Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG nsSlapdPlugin 2022-12-17T23:55:43Z DEBUG extensibleObject 2022-12-17T23:55:43Z DEBUG [] 2022-12-17T23:55:43Z DEBUG Updated 0 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-7_bit_check.update 0.006 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/50-dogtag10-migration.update' 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=aclResources,o=ipaca 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=aclResources,o=ipaca 2022-12-17T23:55:43Z DEBUG resourceACLS: 2022-12-17T23:55:43Z DEBUG certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete 2022-12-17T23:55:43Z DEBUG certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter 2022-12-17T23:55:43Z DEBUG certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log 2022-12-17T23:55:43Z DEBUG certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2022-12-17T23:55:43Z DEBUG certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2022-12-17T23:55:43Z DEBUG certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets 2022-12-17T23:55:43Z DEBUG certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory 2022-12-17T23:55:43Z DEBUG certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate 2022-12-17T23:55:43Z DEBUG certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates 2022-12-17T23:55:43Z DEBUG certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests 2022-12-17T23:55:43Z DEBUG certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request 2022-12-17T23:55:43Z DEBUG certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information 2022-12-17T23:55:43Z DEBUG certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests 2022-12-17T23:55:43Z DEBUG certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl 2022-12-17T23:55:43Z DEBUG certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate 2022-12-17T23:55:43Z DEBUG certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates 2022-12-17T23:55:43Z DEBUG certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain 2022-12-17T23:55:43Z DEBUG certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL 2022-12-17T23:55:43Z DEBUG certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request 2022-12-17T23:55:43Z DEBUG certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status 2022-12-17T23:55:43Z DEBUG certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request 2022-12-17T23:55:43Z DEBUG certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate 2022-12-17T23:55:43Z DEBUG certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request 2022-12-17T23:55:43Z DEBUG certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile 2022-12-17T23:55:43Z DEBUG certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles 2022-12-17T23:55:43Z DEBUG certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile 2022-12-17T23:55:43Z DEBUG certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles 2022-12-17T23:55:43Z DEBUG certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles 2022-12-17T23:55:43Z DEBUG certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests 2022-12-17T23:55:43Z DEBUG certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA 2022-12-17T23:55:43Z DEBUG certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics 2022-12-17T23:55:43Z DEBUG certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups 2022-12-17T23:55:43Z DEBUG certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information 2022-12-17T23:55:43Z DEBUG certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent 2022-12-17T23:55:43Z DEBUG certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration. 2022-12-17T23:55:43Z DEBUG certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration. 2022-12-17T23:55:43Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2022-12-17T23:55:43Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2022-12-17T23:55:43Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2022-12-17T23:55:43Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2022-12-17T23:55:43Z DEBUG certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests. 2022-12-17T23:55:43Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2022-12-17T23:55:43Z DEBUG certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities 2022-12-17T23:55:43Z DEBUG certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities 2022-12-17T23:55:43Z DEBUG certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities 2022-12-17T23:55:43Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2022-12-17T23:55:43Z DEBUG certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities 2022-12-17T23:55:43Z DEBUG certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml 2022-12-17T23:55:43Z DEBUG certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG CertACLS 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG aclResources 2022-12-17T23:55:43Z DEBUG addifexist: 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations'] 2022-12-17T23:55:43Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout'] 2022-12-17T23:55:43Z DEBUG addifexist: 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout'] 2022-12-17T23:55:43Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations'] 2022-12-17T23:55:43Z DEBUG addifexist: 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations'] 2022-12-17T23:55:43Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations'] 2022-12-17T23:55:43Z DEBUG addifexist: 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations'] 2022-12-17T23:55:43Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations'] 2022-12-17T23:55:43Z DEBUG addifexist: 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations'] 2022-12-17T23:55:43Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations'] 2022-12-17T23:55:43Z DEBUG replace: certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group":Anybody is allowed to read domain.xml but only Subsystem group is allowed to modify the domain.xml not found, skipping 2022-12-17T23:55:43Z DEBUG replace: certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml not found, skipping 2022-12-17T23:55:43Z DEBUG replace: certServer.ca.connectorInfo:read,modify:allow (modify,read) group="Enterprise KRA Administrators":Only Enterprise Administrators are allowed to update the connector information not found, skipping 2022-12-17T23:55:43Z DEBUG addifexist: 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations'] 2022-12-17T23:55:43Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=aclResources,o=ipaca 2022-12-17T23:55:43Z DEBUG resourceACLS: 2022-12-17T23:55:43Z DEBUG certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete 2022-12-17T23:55:43Z DEBUG certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter 2022-12-17T23:55:43Z DEBUG certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log 2022-12-17T23:55:43Z DEBUG certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2022-12-17T23:55:43Z DEBUG certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2022-12-17T23:55:43Z DEBUG certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets 2022-12-17T23:55:43Z DEBUG certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify 2022-12-17T23:55:43Z DEBUG certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory 2022-12-17T23:55:43Z DEBUG certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate 2022-12-17T23:55:43Z DEBUG certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates 2022-12-17T23:55:43Z DEBUG certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests 2022-12-17T23:55:43Z DEBUG certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request 2022-12-17T23:55:43Z DEBUG certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information 2022-12-17T23:55:43Z DEBUG certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests 2022-12-17T23:55:43Z DEBUG certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl 2022-12-17T23:55:43Z DEBUG certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate 2022-12-17T23:55:43Z DEBUG certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates 2022-12-17T23:55:43Z DEBUG certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain 2022-12-17T23:55:43Z DEBUG certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL 2022-12-17T23:55:43Z DEBUG certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request 2022-12-17T23:55:43Z DEBUG certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status 2022-12-17T23:55:43Z DEBUG certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request 2022-12-17T23:55:43Z DEBUG certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate 2022-12-17T23:55:43Z DEBUG certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request 2022-12-17T23:55:43Z DEBUG certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile 2022-12-17T23:55:43Z DEBUG certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles 2022-12-17T23:55:43Z DEBUG certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile 2022-12-17T23:55:43Z DEBUG certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles 2022-12-17T23:55:43Z DEBUG certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles 2022-12-17T23:55:43Z DEBUG certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests 2022-12-17T23:55:43Z DEBUG certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA 2022-12-17T23:55:43Z DEBUG certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics 2022-12-17T23:55:43Z DEBUG certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups 2022-12-17T23:55:43Z DEBUG certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information 2022-12-17T23:55:43Z DEBUG certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent 2022-12-17T23:55:43Z DEBUG certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration. 2022-12-17T23:55:43Z DEBUG certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration. 2022-12-17T23:55:43Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2022-12-17T23:55:43Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2022-12-17T23:55:43Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2022-12-17T23:55:43Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2022-12-17T23:55:43Z DEBUG certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests. 2022-12-17T23:55:43Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2022-12-17T23:55:43Z DEBUG certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities 2022-12-17T23:55:43Z DEBUG certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities 2022-12-17T23:55:43Z DEBUG certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities 2022-12-17T23:55:43Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2022-12-17T23:55:43Z DEBUG certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities 2022-12-17T23:55:43Z DEBUG certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators" || group="Security Domain Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml 2022-12-17T23:55:43Z DEBUG certServer.ca.certs:execute:allow (execute) group="Enterprise ACME Administrators":ACME Agents may execute cert operations 2022-12-17T23:55:43Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2022-12-17T23:55:43Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2022-12-17T23:55:43Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2022-12-17T23:55:43Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2022-12-17T23:55:43Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2022-12-17T23:55:43Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG CertACLS 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG aclResources 2022-12-17T23:55:43Z DEBUG [] 2022-12-17T23:55:43Z DEBUG Updated 0 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-dogtag10-migration.update 0.015 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/50-groupuuid.update' 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG posixgroup 2022-12-17T23:55:43Z DEBUG ipausergroup 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG nestedGroup 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG admins 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Account administrators group 2022-12-17T23:55:43Z DEBUG gidNumber: 2022-12-17T23:55:43Z DEBUG 1382800000 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG uid=admin,cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG ipaUniqueID: 2022-12-17T23:55:43Z DEBUG ad1f975a-7e65-11ed-914a-525400000010 2022-12-17T23:55:43Z DEBUG memberOf: 2022-12-17T23:55:43Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Host Enrollment,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG add: 'ipaobject' to objectclass, current value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'ipaobject', 'nestedGroup'] 2022-12-17T23:55:43Z DEBUG add: updated value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'nestedGroup', 'ipaobject'] 2022-12-17T23:55:43Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value ['ad1f975a-7e65-11ed-914a-525400000010'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG posixgroup 2022-12-17T23:55:43Z DEBUG ipausergroup 2022-12-17T23:55:43Z DEBUG nestedGroup 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG admins 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Account administrators group 2022-12-17T23:55:43Z DEBUG gidNumber: 2022-12-17T23:55:43Z DEBUG 1382800000 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG uid=admin,cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG ipaUniqueID: 2022-12-17T23:55:43Z DEBUG ad1f975a-7e65-11ed-914a-525400000010 2022-12-17T23:55:43Z DEBUG memberOf: 2022-12-17T23:55:43Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Write Replication Changelog Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=Host Enrollment,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [] 2022-12-17T23:55:43Z DEBUG Updated 0 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=ipausers,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=ipausers,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG ipausergroup 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Default group for all users 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG ipausers 2022-12-17T23:55:43Z DEBUG ipaUniqueID: 2022-12-17T23:55:43Z DEBUG ad21ece4-7e65-11ed-bdfe-525400000010 2022-12-17T23:55:43Z DEBUG add: 'ipaobject' to objectclass, current value ['top', 'groupofnames', 'nestedgroup', 'ipausergroup', 'ipaobject'] 2022-12-17T23:55:43Z DEBUG add: updated value ['top', 'groupofnames', 'nestedgroup', 'ipausergroup', 'ipaobject'] 2022-12-17T23:55:43Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value ['ad21ece4-7e65-11ed-bdfe-525400000010'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=ipausers,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG ipausergroup 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Default group for all users 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG ipausers 2022-12-17T23:55:43Z DEBUG ipaUniqueID: 2022-12-17T23:55:43Z DEBUG ad21ece4-7e65-11ed-bdfe-525400000010 2022-12-17T23:55:43Z DEBUG [] 2022-12-17T23:55:43Z DEBUG Updated 0 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=editors,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=editors,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG posixgroup 2022-12-17T23:55:43Z DEBUG ipausergroup 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG nestedGroup 2022-12-17T23:55:43Z DEBUG gidNumber: 2022-12-17T23:55:43Z DEBUG 1382800002 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Limited admins who can edit other users 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG editors 2022-12-17T23:55:43Z DEBUG ipaUniqueID: 2022-12-17T23:55:43Z DEBUG ad224158-7e65-11ed-8deb-525400000010 2022-12-17T23:55:43Z DEBUG add: 'ipaobject' to objectclass, current value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'ipaobject', 'nestedGroup'] 2022-12-17T23:55:43Z DEBUG add: updated value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'nestedGroup', 'ipaobject'] 2022-12-17T23:55:43Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value ['ad224158-7e65-11ed-8deb-525400000010'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=editors,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG posixgroup 2022-12-17T23:55:43Z DEBUG ipausergroup 2022-12-17T23:55:43Z DEBUG nestedGroup 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG gidNumber: 2022-12-17T23:55:43Z DEBUG 1382800002 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Limited admins who can edit other users 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG editors 2022-12-17T23:55:43Z DEBUG ipaUniqueID: 2022-12-17T23:55:43Z DEBUG ad224158-7e65-11ed-8deb-525400000010 2022-12-17T23:55:43Z DEBUG [] 2022-12-17T23:55:43Z DEBUG Updated 0 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-groupuuid.update 0.013 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/50-hbacservice.update' 2022-12-17T23:55:43Z DEBUG New entry: cn=crond,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=crond,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectclass: 2022-12-17T23:55:43Z DEBUG ipahbacservice 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG crond 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG crond 2022-12-17T23:55:43Z DEBUG ipauniqueid: 2022-12-17T23:55:43Z DEBUG autogenerate 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=crond,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectclass: 2022-12-17T23:55:43Z DEBUG ipahbacservice 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG crond 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG crond 2022-12-17T23:55:43Z DEBUG ipauniqueid: 2022-12-17T23:55:43Z DEBUG autogenerate 2022-12-17T23:55:43Z DEBUG New entry: cn=vsftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=vsftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectclass: 2022-12-17T23:55:43Z DEBUG ipahbacservice 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG vsftpd 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG vsftpd 2022-12-17T23:55:43Z DEBUG ipauniqueid: 2022-12-17T23:55:43Z DEBUG autogenerate 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=vsftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectclass: 2022-12-17T23:55:43Z DEBUG ipahbacservice 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG vsftpd 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG vsftpd 2022-12-17T23:55:43Z DEBUG ipauniqueid: 2022-12-17T23:55:43Z DEBUG autogenerate 2022-12-17T23:55:43Z DEBUG New entry: cn=proftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=proftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectclass: 2022-12-17T23:55:43Z DEBUG ipahbacservice 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG proftpd 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG proftpd 2022-12-17T23:55:43Z DEBUG ipauniqueid: 2022-12-17T23:55:43Z DEBUG autogenerate 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=proftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectclass: 2022-12-17T23:55:43Z DEBUG ipahbacservice 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG proftpd 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG proftpd 2022-12-17T23:55:43Z DEBUG ipauniqueid: 2022-12-17T23:55:43Z DEBUG autogenerate 2022-12-17T23:55:43Z DEBUG New entry: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectclass: 2022-12-17T23:55:43Z DEBUG ipahbacservice 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG pure-ftpd 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG pure-ftpd 2022-12-17T23:55:43Z DEBUG ipauniqueid: 2022-12-17T23:55:43Z DEBUG autogenerate 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectclass: 2022-12-17T23:55:43Z DEBUG ipahbacservice 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG pure-ftpd 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG pure-ftpd 2022-12-17T23:55:43Z DEBUG ipauniqueid: 2022-12-17T23:55:43Z DEBUG autogenerate 2022-12-17T23:55:43Z DEBUG New entry: cn=gssftp,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=gssftp,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectclass: 2022-12-17T23:55:43Z DEBUG ipahbacservice 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG gssftp 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG gssftp 2022-12-17T23:55:43Z DEBUG ipauniqueid: 2022-12-17T23:55:43Z DEBUG autogenerate 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=gssftp,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectclass: 2022-12-17T23:55:43Z DEBUG ipahbacservice 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG gssftp 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG gssftp 2022-12-17T23:55:43Z DEBUG ipauniqueid: 2022-12-17T23:55:43Z DEBUG autogenerate 2022-12-17T23:55:43Z DEBUG New entry: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG ipahbacservicegroup 2022-12-17T23:55:43Z DEBUG nestedGroup 2022-12-17T23:55:43Z DEBUG groupOfNames 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG ftp 2022-12-17T23:55:43Z DEBUG ipauniqueid: 2022-12-17T23:55:43Z DEBUG autogenerate 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Default group of ftp related services 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=ftp,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=proftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=vsftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=gssftp,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG ipahbacservicegroup 2022-12-17T23:55:43Z DEBUG nestedGroup 2022-12-17T23:55:43Z DEBUG groupOfNames 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG ftp 2022-12-17T23:55:43Z DEBUG ipauniqueid: 2022-12-17T23:55:43Z DEBUG autogenerate 2022-12-17T23:55:43Z DEBUG description: 2022-12-17T23:55:43Z DEBUG Default group of ftp related services 2022-12-17T23:55:43Z DEBUG member: 2022-12-17T23:55:43Z DEBUG cn=ftp,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=proftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=vsftpd,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn=gssftp,cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-hbacservice.update 0.043 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/50-ipaconfig.update' 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=ipaConfig,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=ipaConfig,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nsContainer 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG ipaGuiConfig 2022-12-17T23:55:43Z DEBUG ipaConfigObject 2022-12-17T23:55:43Z DEBUG ipaUserSearchFields: 2022-12-17T23:55:43Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2022-12-17T23:55:43Z DEBUG ipaGroupSearchFields: 2022-12-17T23:55:43Z DEBUG cn,description 2022-12-17T23:55:43Z DEBUG ipaSearchTimeLimit: 2022-12-17T23:55:43Z DEBUG 2 2022-12-17T23:55:43Z DEBUG ipaSearchRecordsLimit: 2022-12-17T23:55:43Z DEBUG 100 2022-12-17T23:55:43Z DEBUG ipaHomesRootDir: 2022-12-17T23:55:43Z DEBUG /home 2022-12-17T23:55:43Z DEBUG ipaDefaultLoginShell: 2022-12-17T23:55:43Z DEBUG /bin/sh 2022-12-17T23:55:43Z DEBUG ipaDefaultPrimaryGroup: 2022-12-17T23:55:43Z DEBUG ipausers 2022-12-17T23:55:43Z DEBUG ipaMaxUsernameLength: 2022-12-17T23:55:43Z DEBUG 32 2022-12-17T23:55:43Z DEBUG ipaMaxHostnameLength: 2022-12-17T23:55:43Z DEBUG 64 2022-12-17T23:55:43Z DEBUG ipaPwdExpAdvNotify: 2022-12-17T23:55:43Z DEBUG 4 2022-12-17T23:55:43Z DEBUG ipaGroupObjectClasses: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG ipausergroup 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG ipaUserObjectClasses: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG person 2022-12-17T23:55:43Z DEBUG organizationalperson 2022-12-17T23:55:43Z DEBUG inetorgperson 2022-12-17T23:55:43Z DEBUG inetuser 2022-12-17T23:55:43Z DEBUG posixaccount 2022-12-17T23:55:43Z DEBUG krbprincipalaux 2022-12-17T23:55:43Z DEBUG krbticketpolicyaux 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG ipasshuser 2022-12-17T23:55:43Z DEBUG ipaDefaultEmailDomain: 2022-12-17T23:55:43Z DEBUG redacted_domain.com 2022-12-17T23:55:43Z DEBUG ipaMigrationEnabled: 2022-12-17T23:55:43Z DEBUG FALSE 2022-12-17T23:55:43Z DEBUG ipaConfigString: 2022-12-17T23:55:43Z DEBUG AllowNThash 2022-12-17T23:55:43Z DEBUG KDC:Disable Last Success 2022-12-17T23:55:43Z DEBUG ipaSELinuxUserMapOrder: 2022-12-17T23:55:43Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2022-12-17T23:55:43Z DEBUG ipaSELinuxUserMapDefault: 2022-12-17T23:55:43Z DEBUG unconfined_u:s0-s0:c0.c1023 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG ipaConfig 2022-12-17T23:55:43Z DEBUG ipaCertificateSubjectBase: 2022-12-17T23:55:43Z DEBUG O=REDACTED_DOMAIN.COM 2022-12-17T23:55:43Z DEBUG replace: guest_u:s0$$xguest_u:s0$$user_u:s0$$staff_u:s0-s0:c0.c1023$$sysadm_u:s0-s0:c0.c1023$$unconfined_u:s0-s0:c0.c1023 not found, skipping 2022-12-17T23:55:43Z DEBUG replace: ipaSELinuxUserMapOrder: guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 not found, skipping 2022-12-17T23:55:43Z DEBUG replace: guest_u:s0$xguest_u:s0$user_u:s0-s0:c0.c1023$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 not found, skipping 2022-12-17T23:55:43Z DEBUG add: 'unconfined_u:s0-s0:c0.c1023' to ipaSELinuxUserMapDefault, current value ['unconfined_u:s0-s0:c0.c1023'] 2022-12-17T23:55:43Z DEBUG add: updated value ['unconfined_u:s0-s0:c0.c1023'] 2022-12-17T23:55:43Z DEBUG add: 'ipasshuser' to ipaUserObjectClasses, current value ['top', 'person', 'organizationalperson', 'inetorgperson', 'inetuser', 'posixaccount', 'krbprincipalaux', 'krbticketpolicyaux', 'ipaobject', 'ipasshuser'] 2022-12-17T23:55:43Z DEBUG add: updated value ['top', 'person', 'organizationalperson', 'inetorgperson', 'inetuser', 'posixaccount', 'krbprincipalaux', 'krbticketpolicyaux', 'ipaobject', 'ipasshuser'] 2022-12-17T23:55:43Z DEBUG remove: 'AllowLMhash' from ipaConfigString, current value ['AllowNThash', 'KDC:Disable Last Success'] 2022-12-17T23:55:43Z DEBUG remove: 'AllowLMhash' not in ipaConfigString 2022-12-17T23:55:43Z DEBUG add: 'ipaUserAuthTypeClass' to objectClass, current value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject'] 2022-12-17T23:55:43Z DEBUG add: updated value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject', 'ipaUserAuthTypeClass'] 2022-12-17T23:55:43Z DEBUG add: 'ipaNameResolutionData' to objectClass, current value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject', 'ipaUserAuthTypeClass'] 2022-12-17T23:55:43Z DEBUG add: updated value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject', 'ipaUserAuthTypeClass', 'ipaNameResolutionData'] 2022-12-17T23:55:43Z DEBUG addifnew: '64' to ipamaxhostnamelength, current value ['64'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=ipaConfig,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG nsContainer 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG ipaGuiConfig 2022-12-17T23:55:43Z DEBUG ipaConfigObject 2022-12-17T23:55:43Z DEBUG ipaUserAuthTypeClass 2022-12-17T23:55:43Z DEBUG ipaNameResolutionData 2022-12-17T23:55:43Z DEBUG ipaUserSearchFields: 2022-12-17T23:55:43Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2022-12-17T23:55:43Z DEBUG ipaGroupSearchFields: 2022-12-17T23:55:43Z DEBUG cn,description 2022-12-17T23:55:43Z DEBUG ipaSearchTimeLimit: 2022-12-17T23:55:43Z DEBUG 2 2022-12-17T23:55:43Z DEBUG ipaSearchRecordsLimit: 2022-12-17T23:55:43Z DEBUG 100 2022-12-17T23:55:43Z DEBUG ipaHomesRootDir: 2022-12-17T23:55:43Z DEBUG /home 2022-12-17T23:55:43Z DEBUG ipaDefaultLoginShell: 2022-12-17T23:55:43Z DEBUG /bin/sh 2022-12-17T23:55:43Z DEBUG ipaDefaultPrimaryGroup: 2022-12-17T23:55:43Z DEBUG ipausers 2022-12-17T23:55:43Z DEBUG ipaMaxUsernameLength: 2022-12-17T23:55:43Z DEBUG 32 2022-12-17T23:55:43Z DEBUG ipaMaxHostnameLength: 2022-12-17T23:55:43Z DEBUG 64 2022-12-17T23:55:43Z DEBUG ipaPwdExpAdvNotify: 2022-12-17T23:55:43Z DEBUG 4 2022-12-17T23:55:43Z DEBUG ipaGroupObjectClasses: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG groupofnames 2022-12-17T23:55:43Z DEBUG nestedgroup 2022-12-17T23:55:43Z DEBUG ipausergroup 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG ipaUserObjectClasses: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG person 2022-12-17T23:55:43Z DEBUG organizationalperson 2022-12-17T23:55:43Z DEBUG inetorgperson 2022-12-17T23:55:43Z DEBUG inetuser 2022-12-17T23:55:43Z DEBUG posixaccount 2022-12-17T23:55:43Z DEBUG krbprincipalaux 2022-12-17T23:55:43Z DEBUG krbticketpolicyaux 2022-12-17T23:55:43Z DEBUG ipaobject 2022-12-17T23:55:43Z DEBUG ipasshuser 2022-12-17T23:55:43Z DEBUG ipaDefaultEmailDomain: 2022-12-17T23:55:43Z DEBUG redacted_domain.com 2022-12-17T23:55:43Z DEBUG ipaMigrationEnabled: 2022-12-17T23:55:43Z DEBUG FALSE 2022-12-17T23:55:43Z DEBUG ipaConfigString: 2022-12-17T23:55:43Z DEBUG AllowNThash 2022-12-17T23:55:43Z DEBUG KDC:Disable Last Success 2022-12-17T23:55:43Z DEBUG ipaSELinuxUserMapOrder: 2022-12-17T23:55:43Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2022-12-17T23:55:43Z DEBUG ipaSELinuxUserMapDefault: 2022-12-17T23:55:43Z DEBUG unconfined_u:s0-s0:c0.c1023 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG ipaConfig 2022-12-17T23:55:43Z DEBUG ipaCertificateSubjectBase: 2022-12-17T23:55:43Z DEBUG O=REDACTED_DOMAIN.COM 2022-12-17T23:55:43Z DEBUG [(0, 'objectClass', ['ipaUserAuthTypeClass', 'ipaNameResolutionData'])] 2022-12-17T23:55:43Z DEBUG Updated 1 2022-12-17T23:55:43Z DEBUG update_entry modlist [(0, 'objectClass', [b'ipaUserAuthTypeClass', b'ipaNameResolutionData'])] 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-ipaconfig.update 0.013 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/50-krbenctypes.update' 2022-12-17T23:55:43Z DEBUG Updating existing entry: cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG REDACTED_DOMAIN.COM 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG krbrealmcontainer 2022-12-17T23:55:43Z DEBUG krbticketpolicyaux 2022-12-17T23:55:43Z DEBUG krbSubTrees: 2022-12-17T23:55:43Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG krbSearchScope: 2022-12-17T23:55:43Z DEBUG 2 2022-12-17T23:55:43Z DEBUG krbSupportedEncSaltTypes: 2022-12-17T23:55:43Z DEBUG aes256-cts:normal 2022-12-17T23:55:43Z DEBUG aes256-cts:special 2022-12-17T23:55:43Z DEBUG aes128-cts:normal 2022-12-17T23:55:43Z DEBUG aes128-cts:special 2022-12-17T23:55:43Z DEBUG aes128-sha2:normal 2022-12-17T23:55:43Z DEBUG aes128-sha2:special 2022-12-17T23:55:43Z DEBUG aes256-sha2:normal 2022-12-17T23:55:43Z DEBUG aes256-sha2:special 2022-12-17T23:55:43Z DEBUG camellia128-cts-cmac:normal 2022-12-17T23:55:43Z DEBUG camellia128-cts-cmac:special 2022-12-17T23:55:43Z DEBUG camellia256-cts-cmac:normal 2022-12-17T23:55:43Z DEBUG camellia256-cts-cmac:special 2022-12-17T23:55:43Z DEBUG krbMaxTicketLife: 2022-12-17T23:55:43Z DEBUG 86400 2022-12-17T23:55:43Z DEBUG krbMaxRenewableAge: 2022-12-17T23:55:43Z DEBUG 604800 2022-12-17T23:55:43Z DEBUG krbDefaultEncSaltTypes: 2022-12-17T23:55:43Z DEBUG aes256-sha2:special 2022-12-17T23:55:43Z DEBUG aes128-sha2:special 2022-12-17T23:55:43Z DEBUG aes256-cts:special 2022-12-17T23:55:43Z DEBUG aes128-cts:special 2022-12-17T23:55:43Z DEBUG krbMKey: 2022-12-17T23:55:43Z DEBUG XXXXXXXX 2022-12-17T23:55:43Z DEBUG krbPwdPolicyReference: 2022-12-17T23:55:43Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG add: 'camellia128-cts-cmac:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special'] 2022-12-17T23:55:43Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal'] 2022-12-17T23:55:43Z DEBUG add: 'camellia128-cts-cmac:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal'] 2022-12-17T23:55:43Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special'] 2022-12-17T23:55:43Z DEBUG add: 'camellia256-cts-cmac:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special'] 2022-12-17T23:55:43Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal'] 2022-12-17T23:55:43Z DEBUG add: 'camellia256-cts-cmac:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal'] 2022-12-17T23:55:43Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special'] 2022-12-17T23:55:43Z DEBUG add: 'aes128-sha2:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special'] 2022-12-17T23:55:43Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal'] 2022-12-17T23:55:43Z DEBUG add: 'aes128-sha2:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal'] 2022-12-17T23:55:43Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special'] 2022-12-17T23:55:43Z DEBUG add: 'aes256-sha2:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special'] 2022-12-17T23:55:43Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal'] 2022-12-17T23:55:43Z DEBUG add: 'aes256-sha2:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal'] 2022-12-17T23:55:43Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG REDACTED_DOMAIN.COM 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG krbrealmcontainer 2022-12-17T23:55:43Z DEBUG krbticketpolicyaux 2022-12-17T23:55:43Z DEBUG krbSubTrees: 2022-12-17T23:55:43Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG krbSearchScope: 2022-12-17T23:55:43Z DEBUG 2 2022-12-17T23:55:43Z DEBUG krbSupportedEncSaltTypes: 2022-12-17T23:55:43Z DEBUG aes256-cts:normal 2022-12-17T23:55:43Z DEBUG aes256-cts:special 2022-12-17T23:55:43Z DEBUG aes128-cts:normal 2022-12-17T23:55:43Z DEBUG aes128-cts:special 2022-12-17T23:55:43Z DEBUG camellia128-cts-cmac:normal 2022-12-17T23:55:43Z DEBUG camellia128-cts-cmac:special 2022-12-17T23:55:43Z DEBUG camellia256-cts-cmac:normal 2022-12-17T23:55:43Z DEBUG camellia256-cts-cmac:special 2022-12-17T23:55:43Z DEBUG aes128-sha2:normal 2022-12-17T23:55:43Z DEBUG aes128-sha2:special 2022-12-17T23:55:43Z DEBUG aes256-sha2:normal 2022-12-17T23:55:43Z DEBUG aes256-sha2:special 2022-12-17T23:55:43Z DEBUG krbMaxTicketLife: 2022-12-17T23:55:43Z DEBUG 86400 2022-12-17T23:55:43Z DEBUG krbMaxRenewableAge: 2022-12-17T23:55:43Z DEBUG 604800 2022-12-17T23:55:43Z DEBUG krbDefaultEncSaltTypes: 2022-12-17T23:55:43Z DEBUG aes256-sha2:special 2022-12-17T23:55:43Z DEBUG aes128-sha2:special 2022-12-17T23:55:43Z DEBUG aes256-cts:special 2022-12-17T23:55:43Z DEBUG aes128-cts:special 2022-12-17T23:55:43Z DEBUG krbMKey: 2022-12-17T23:55:43Z DEBUG XXXXXXXX 2022-12-17T23:55:43Z DEBUG krbPwdPolicyReference: 2022-12-17T23:55:43Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG [] 2022-12-17T23:55:43Z DEBUG Updated 0 2022-12-17T23:55:43Z DEBUG Done 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-krbenctypes.update 0.007 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/50-nis.update' 2022-12-17T23:55:43Z DEBUG Executing upgrade plugin: update_nis_configuration 2022-12-17T23:55:43Z DEBUG raw: update_nis_configuration 2022-12-17T23:55:43Z DEBUG Skipping NIS update, NIS Server is not configured 2022-12-17T23:55:43Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:43Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:43Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-nis.update 0.002 sec 2022-12-17T23:55:43Z DEBUG Parsing update file '/usr/share/ipa/updates/55-pbacmemberof.update' 2022-12-17T23:55:43Z DEBUG New entry: cn=Update PBAC memberOf 138906141,cn=memberof task,cn=tasks,cn=config 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Initial value 2022-12-17T23:55:43Z DEBUG dn: cn=Update PBAC memberOf 138906141,cn=memberof task,cn=tasks,cn=config 2022-12-17T23:55:43Z DEBUG add: 'top' to objectClass, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['top'] 2022-12-17T23:55:43Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2022-12-17T23:55:43Z DEBUG add: updated value ['top', 'extensibleObject'] 2022-12-17T23:55:43Z DEBUG add: 'IPA PBAC memberOf 138906141' to cn, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['IPA PBAC memberOf 138906141'] 2022-12-17T23:55:43Z DEBUG add: 'cn=privileges,cn=pbac,dc=redacted_domain,dc=com' to basedn, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['cn=privileges,cn=pbac,dc=redacted_domain,dc=com'] 2022-12-17T23:55:43Z DEBUG add: '(objectclass=*)' to filter, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['(objectclass=*)'] 2022-12-17T23:55:43Z DEBUG add: '10' to ttl, current value [] 2022-12-17T23:55:43Z DEBUG add: updated value ['10'] 2022-12-17T23:55:43Z DEBUG --------------------------------------------- 2022-12-17T23:55:43Z DEBUG Final value after applying updates 2022-12-17T23:55:43Z DEBUG dn: cn=Update PBAC memberOf 138906141,cn=memberof task,cn=tasks,cn=config 2022-12-17T23:55:43Z DEBUG objectClass: 2022-12-17T23:55:43Z DEBUG top 2022-12-17T23:55:43Z DEBUG extensibleObject 2022-12-17T23:55:43Z DEBUG cn: 2022-12-17T23:55:43Z DEBUG IPA PBAC memberOf 138906141 2022-12-17T23:55:43Z DEBUG basedn: 2022-12-17T23:55:43Z DEBUG cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:43Z DEBUG filter: 2022-12-17T23:55:43Z DEBUG (objectclass=*) 2022-12-17T23:55:43Z DEBUG ttl: 2022-12-17T23:55:43Z DEBUG 10 2022-12-17T23:55:44Z DEBUG New entry: cn=Update Role memberOf 138906141,cn=memberof task,cn=tasks,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=Update Role memberOf 138906141,cn=memberof task,cn=tasks,cn=config 2022-12-17T23:55:44Z DEBUG add: 'top' to objectClass, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['top'] 2022-12-17T23:55:44Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2022-12-17T23:55:44Z DEBUG add: updated value ['top', 'extensibleObject'] 2022-12-17T23:55:44Z DEBUG add: 'Update Role memberOf 138906141' to cn, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['Update Role memberOf 138906141'] 2022-12-17T23:55:44Z DEBUG add: 'cn=roles,cn=accounts,dc=redacted_domain,dc=com' to basedn, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=roles,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: '(objectclass=*)' to filter, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['(objectclass=*)'] 2022-12-17T23:55:44Z DEBUG add: '10' to ttl, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['10'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=Update Role memberOf 138906141,cn=memberof task,cn=tasks,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Update Role memberOf 138906141 2022-12-17T23:55:44Z DEBUG basedn: 2022-12-17T23:55:44Z DEBUG cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG filter: 2022-12-17T23:55:44Z DEBUG (objectclass=*) 2022-12-17T23:55:44Z DEBUG ttl: 2022-12-17T23:55:44Z DEBUG 10 2022-12-17T23:55:44Z ERROR Add failure Server is unwilling to perform: 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/55-pbacmemberof.update 0.074 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/59-trusts-sysacount.update' 2022-12-17T23:55:44Z DEBUG New entry: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG GroupOfNames 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG adtrust agents 2022-12-17T23:55:44Z DEBUG add: 'nestedgroup' to objectClass, current value ['GroupOfNames', 'top'] 2022-12-17T23:55:44Z DEBUG add: updated value ['GroupOfNames', 'top', 'nestedgroup'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG GroupOfNames 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG adtrust agents 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/59-trusts-sysacount.update 0.005 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/60-trusts.update' 2022-12-17T23:55:44Z DEBUG New entry: cn=trust admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=trust admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG ipausergroup 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG ipaobject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG trust admins 2022-12-17T23:55:44Z DEBUG description: 2022-12-17T23:55:44Z DEBUG Trusts administrators group 2022-12-17T23:55:44Z DEBUG member: 2022-12-17T23:55:44Z DEBUG uid=admin,cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG nsAccountLock: 2022-12-17T23:55:44Z DEBUG FALSE 2022-12-17T23:55:44Z DEBUG ipaUniqueID: 2022-12-17T23:55:44Z DEBUG autogenerate 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=trust admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG ipausergroup 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG ipaobject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG trust admins 2022-12-17T23:55:44Z DEBUG description: 2022-12-17T23:55:44Z DEBUG Trusts administrators group 2022-12-17T23:55:44Z DEBUG member: 2022-12-17T23:55:44Z DEBUG uid=admin,cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG nsAccountLock: 2022-12-17T23:55:44Z DEBUG FALSE 2022-12-17T23:55:44Z DEBUG ipaUniqueID: 2022-12-17T23:55:44Z DEBUG autogenerate 2022-12-17T23:55:44Z DEBUG New entry: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ADTrust Agents 2022-12-17T23:55:44Z DEBUG description: 2022-12-17T23:55:44Z DEBUG System accounts able to access trust information 2022-12-17T23:55:44Z DEBUG member: 2022-12-17T23:55:44Z DEBUG cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ADTrust Agents 2022-12-17T23:55:44Z DEBUG description: 2022-12-17T23:55:44Z DEBUG System accounts able to access trust information 2022-12-17T23:55:44Z DEBUG member: 2022-12-17T23:55:44Z DEBUG cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG New entry: cn=trusts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=trusts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG trusts 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=trusts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG trusts 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=trusts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=trusts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG trusts 2022-12-17T23:55:44Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2022-12-17T23:55:44Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG add: '(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG replace: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG replace: (target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) not found, skipping 2022-12-17T23:55:44Z DEBUG add: '(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG add: '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=trusts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG trusts 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG [(2, 'aci', ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', '(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', b'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', b'(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', b'(target = "ldap:///cn=trusts,dc=redacted_domain,dc=com")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', b'(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG domain 2022-12-17T23:55:44Z DEBUG pilotObject 2022-12-17T23:55:44Z DEBUG domainRelatedObject 2022-12-17T23:55:44Z DEBUG nisDomainObject 2022-12-17T23:55:44Z DEBUG dc: 2022-12-17T23:55:44Z DEBUG redacted_domain 2022-12-17T23:55:44Z DEBUG info: 2022-12-17T23:55:44Z DEBUG IPA V2.0 2022-12-17T23:55:44Z DEBUG associatedDomain: 2022-12-17T23:55:44Z DEBUG redacted_domain.com 2022-12-17T23:55:44Z DEBUG nisDomain: 2022-12-17T23:55:44Z DEBUG redacted_domain.com 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:44Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:44Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:44Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:44Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG add: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG remove: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read NT passwords"; allow (read) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG remove: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read NT passwords"; allow (read) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG domain 2022-12-17T23:55:44Z DEBUG pilotObject 2022-12-17T23:55:44Z DEBUG domainRelatedObject 2022-12-17T23:55:44Z DEBUG nisDomainObject 2022-12-17T23:55:44Z DEBUG dc: 2022-12-17T23:55:44Z DEBUG redacted_domain 2022-12-17T23:55:44Z DEBUG info: 2022-12-17T23:55:44Z DEBUG IPA V2.0 2022-12-17T23:55:44Z DEBUG associatedDomain: 2022-12-17T23:55:44Z DEBUG redacted_domain.com 2022-12-17T23:55:44Z DEBUG nisDomain: 2022-12-17T23:55:44Z DEBUG redacted_domain.com 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:44Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:44Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:44Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:44Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG [(0, 'aci', ['(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG accounts 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2022-12-17T23:55:44Z DEBUG add: '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about users and group objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about users and group objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG accounts 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2022-12-17T23:55:44Z DEBUG (targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about users and group objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG [(0, 'aci', ['(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about users and group objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about users and group objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG services 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2022-12-17T23:55:44Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG add: '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com" or userattr="managedby#SELFDN";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com" or userattr="managedby#SELFDN";)'] 2022-12-17T23:55:44Z DEBUG add: '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com" or userattr="managedby#SELFDN";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com" or userattr="managedby#SELFDN";)'] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com" or userattr="managedby#SELFDN";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com" or userattr="managedby#SELFDN";)'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG services 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2022-12-17T23:55:44Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com" or userattr="managedby#SELFDN";) 2022-12-17T23:55:44Z DEBUG (target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com" or userattr="managedby#SELFDN";) 2022-12-17T23:55:44Z DEBUG [(0, 'aci', ['(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com" or userattr="managedby#SELFDN";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com" or userattr="managedby#SELFDN";)'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(0, 'aci', [b'(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com" or userattr="managedby#SELFDN";)', b'(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=redacted_domain,dc=com" or userattr="managedby#SELFDN";)'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=ipaConfig,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=ipaConfig,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG ipaGuiConfig 2022-12-17T23:55:44Z DEBUG ipaConfigObject 2022-12-17T23:55:44Z DEBUG ipaUserAuthTypeClass 2022-12-17T23:55:44Z DEBUG ipaNameResolutionData 2022-12-17T23:55:44Z DEBUG ipaUserSearchFields: 2022-12-17T23:55:44Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2022-12-17T23:55:44Z DEBUG ipaGroupSearchFields: 2022-12-17T23:55:44Z DEBUG cn,description 2022-12-17T23:55:44Z DEBUG ipaSearchTimeLimit: 2022-12-17T23:55:44Z DEBUG 2 2022-12-17T23:55:44Z DEBUG ipaSearchRecordsLimit: 2022-12-17T23:55:44Z DEBUG 100 2022-12-17T23:55:44Z DEBUG ipaHomesRootDir: 2022-12-17T23:55:44Z DEBUG /home 2022-12-17T23:55:44Z DEBUG ipaDefaultLoginShell: 2022-12-17T23:55:44Z DEBUG /bin/sh 2022-12-17T23:55:44Z DEBUG ipaDefaultPrimaryGroup: 2022-12-17T23:55:44Z DEBUG ipausers 2022-12-17T23:55:44Z DEBUG ipaMaxUsernameLength: 2022-12-17T23:55:44Z DEBUG 32 2022-12-17T23:55:44Z DEBUG ipaMaxHostnameLength: 2022-12-17T23:55:44Z DEBUG 64 2022-12-17T23:55:44Z DEBUG ipaPwdExpAdvNotify: 2022-12-17T23:55:44Z DEBUG 4 2022-12-17T23:55:44Z DEBUG ipaGroupObjectClasses: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG ipausergroup 2022-12-17T23:55:44Z DEBUG ipaobject 2022-12-17T23:55:44Z DEBUG ipaUserObjectClasses: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG person 2022-12-17T23:55:44Z DEBUG organizationalperson 2022-12-17T23:55:44Z DEBUG inetorgperson 2022-12-17T23:55:44Z DEBUG inetuser 2022-12-17T23:55:44Z DEBUG posixaccount 2022-12-17T23:55:44Z DEBUG krbprincipalaux 2022-12-17T23:55:44Z DEBUG krbticketpolicyaux 2022-12-17T23:55:44Z DEBUG ipaobject 2022-12-17T23:55:44Z DEBUG ipasshuser 2022-12-17T23:55:44Z DEBUG ipaDefaultEmailDomain: 2022-12-17T23:55:44Z DEBUG redacted_domain.com 2022-12-17T23:55:44Z DEBUG ipaMigrationEnabled: 2022-12-17T23:55:44Z DEBUG FALSE 2022-12-17T23:55:44Z DEBUG ipaConfigString: 2022-12-17T23:55:44Z DEBUG AllowNThash 2022-12-17T23:55:44Z DEBUG KDC:Disable Last Success 2022-12-17T23:55:44Z DEBUG ipaSELinuxUserMapOrder: 2022-12-17T23:55:44Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2022-12-17T23:55:44Z DEBUG ipaSELinuxUserMapDefault: 2022-12-17T23:55:44Z DEBUG unconfined_u:s0-s0:c0.c1023 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ipaConfig 2022-12-17T23:55:44Z DEBUG ipaCertificateSubjectBase: 2022-12-17T23:55:44Z DEBUG O=REDACTED_DOMAIN.COM 2022-12-17T23:55:44Z DEBUG addifnew: 'MS-PAC' to ipaKrbAuthzData, current value [] 2022-12-17T23:55:44Z DEBUG addifnew: set ipaKrbAuthzData to ['MS-PAC'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=ipaConfig,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG ipaGuiConfig 2022-12-17T23:55:44Z DEBUG ipaConfigObject 2022-12-17T23:55:44Z DEBUG ipaUserAuthTypeClass 2022-12-17T23:55:44Z DEBUG ipaNameResolutionData 2022-12-17T23:55:44Z DEBUG ipaUserSearchFields: 2022-12-17T23:55:44Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2022-12-17T23:55:44Z DEBUG ipaGroupSearchFields: 2022-12-17T23:55:44Z DEBUG cn,description 2022-12-17T23:55:44Z DEBUG ipaSearchTimeLimit: 2022-12-17T23:55:44Z DEBUG 2 2022-12-17T23:55:44Z DEBUG ipaSearchRecordsLimit: 2022-12-17T23:55:44Z DEBUG 100 2022-12-17T23:55:44Z DEBUG ipaHomesRootDir: 2022-12-17T23:55:44Z DEBUG /home 2022-12-17T23:55:44Z DEBUG ipaDefaultLoginShell: 2022-12-17T23:55:44Z DEBUG /bin/sh 2022-12-17T23:55:44Z DEBUG ipaDefaultPrimaryGroup: 2022-12-17T23:55:44Z DEBUG ipausers 2022-12-17T23:55:44Z DEBUG ipaMaxUsernameLength: 2022-12-17T23:55:44Z DEBUG 32 2022-12-17T23:55:44Z DEBUG ipaMaxHostnameLength: 2022-12-17T23:55:44Z DEBUG 64 2022-12-17T23:55:44Z DEBUG ipaPwdExpAdvNotify: 2022-12-17T23:55:44Z DEBUG 4 2022-12-17T23:55:44Z DEBUG ipaGroupObjectClasses: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG ipausergroup 2022-12-17T23:55:44Z DEBUG ipaobject 2022-12-17T23:55:44Z DEBUG ipaUserObjectClasses: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG person 2022-12-17T23:55:44Z DEBUG organizationalperson 2022-12-17T23:55:44Z DEBUG inetorgperson 2022-12-17T23:55:44Z DEBUG inetuser 2022-12-17T23:55:44Z DEBUG posixaccount 2022-12-17T23:55:44Z DEBUG krbprincipalaux 2022-12-17T23:55:44Z DEBUG krbticketpolicyaux 2022-12-17T23:55:44Z DEBUG ipaobject 2022-12-17T23:55:44Z DEBUG ipasshuser 2022-12-17T23:55:44Z DEBUG ipaDefaultEmailDomain: 2022-12-17T23:55:44Z DEBUG redacted_domain.com 2022-12-17T23:55:44Z DEBUG ipaMigrationEnabled: 2022-12-17T23:55:44Z DEBUG FALSE 2022-12-17T23:55:44Z DEBUG ipaConfigString: 2022-12-17T23:55:44Z DEBUG AllowNThash 2022-12-17T23:55:44Z DEBUG KDC:Disable Last Success 2022-12-17T23:55:44Z DEBUG ipaSELinuxUserMapOrder: 2022-12-17T23:55:44Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$sysadm_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2022-12-17T23:55:44Z DEBUG ipaSELinuxUserMapDefault: 2022-12-17T23:55:44Z DEBUG unconfined_u:s0-s0:c0.c1023 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ipaConfig 2022-12-17T23:55:44Z DEBUG ipaCertificateSubjectBase: 2022-12-17T23:55:44Z DEBUG O=REDACTED_DOMAIN.COM 2022-12-17T23:55:44Z DEBUG ipaKrbAuthzData: 2022-12-17T23:55:44Z DEBUG MS-PAC 2022-12-17T23:55:44Z DEBUG [(2, 'ipaKrbAuthzData', ['MS-PAC'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(2, 'ipaKrbAuthzData', [b'MS-PAC'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/60-trusts.update 0.080 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/61-trusts-s4u2proxy.update' 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG groupOfPrincipals 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ipa-cifs-delegation-targets 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG groupOfPrincipals 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ipa-cifs-delegation-targets 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG ipaKrb5DelegationACL 2022-12-17T23:55:44Z DEBUG groupOfPrincipals 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ipa-http-delegation 2022-12-17T23:55:44Z DEBUG memberPrincipal: 2022-12-17T23:55:44Z DEBUG HTTP/master.redacted_domain.com@REDACTED_DOMAIN.COM 2022-12-17T23:55:44Z DEBUG ipaAllowedTarget: 2022-12-17T23:55:44Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG add: 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com' to ipaAllowedTarget, current value ['cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com', 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com', 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG ipaKrb5DelegationACL 2022-12-17T23:55:44Z DEBUG groupOfPrincipals 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ipa-http-delegation 2022-12-17T23:55:44Z DEBUG memberPrincipal: 2022-12-17T23:55:44Z DEBUG HTTP/master.redacted_domain.com@REDACTED_DOMAIN.COM 2022-12-17T23:55:44Z DEBUG ipaAllowedTarget: 2022-12-17T23:55:44Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/61-trusts-s4u2proxy.update 0.005 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/62-ranges.update' 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=ranges,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=ranges,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ranges 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=ranges,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ranges 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=IPA Range-Check,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=IPA Range-Check,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG IPA Range-Check 2022-12-17T23:55:44Z DEBUG nsslapd-basedn: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:44Z DEBUG database 2022-12-17T23:55:44Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:44Z DEBUG Check if newly added or modified ID ranges do not overlap with existing ones 2022-12-17T23:55:44Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:44Z DEBUG on 2022-12-17T23:55:44Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:44Z DEBUG IPA ID range check plugin 2022-12-17T23:55:44Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:44Z DEBUG ipa_range_check_init 2022-12-17T23:55:44Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:44Z DEBUG libipa_range_check 2022-12-17T23:55:44Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:44Z DEBUG preoperation 2022-12-17T23:55:44Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:44Z DEBUG FreeIPA project 2022-12-17T23:55:44Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:44Z DEBUG FreeIPA/1.0 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsSlapdPlugin 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=IPA Range-Check,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG IPA Range-Check 2022-12-17T23:55:44Z DEBUG nsslapd-basedn: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:44Z DEBUG database 2022-12-17T23:55:44Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:44Z DEBUG Check if newly added or modified ID ranges do not overlap with existing ones 2022-12-17T23:55:44Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:44Z DEBUG on 2022-12-17T23:55:44Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:44Z DEBUG IPA ID range check plugin 2022-12-17T23:55:44Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:44Z DEBUG ipa_range_check_init 2022-12-17T23:55:44Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:44Z DEBUG libipa_range_check 2022-12-17T23:55:44Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:44Z DEBUG preoperation 2022-12-17T23:55:44Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:44Z DEBUG FreeIPA project 2022-12-17T23:55:44Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:44Z DEBUG FreeIPA/1.0 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsSlapdPlugin 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Posix IDs 2022-12-17T23:55:44Z DEBUG dnaExcludeScope: 2022-12-17T23:55:44Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG dnaFilter: 2022-12-17T23:55:44Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2022-12-17T23:55:44Z DEBUG dnaMagicRegen: 2022-12-17T23:55:44Z DEBUG -1 2022-12-17T23:55:44Z DEBUG dnaMaxValue: 2022-12-17T23:55:44Z DEBUG 1382999999 2022-12-17T23:55:44Z DEBUG dnaNextValue: 2022-12-17T23:55:44Z DEBUG 1382800000 2022-12-17T23:55:44Z DEBUG dnaScope: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG dnaSharedCfgDN: 2022-12-17T23:55:44Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG dnaThreshold: 2022-12-17T23:55:44Z DEBUG 500 2022-12-17T23:55:44Z DEBUG dnaType: 2022-12-17T23:55:44Z DEBUG uidNumber 2022-12-17T23:55:44Z DEBUG gidNumber 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG replace: (|(objectclass=posixAccount)(objectClass=posixGroup)) not found, skipping 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Posix IDs 2022-12-17T23:55:44Z DEBUG dnaExcludeScope: 2022-12-17T23:55:44Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG dnaFilter: 2022-12-17T23:55:44Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2022-12-17T23:55:44Z DEBUG dnaMagicRegen: 2022-12-17T23:55:44Z DEBUG -1 2022-12-17T23:55:44Z DEBUG dnaMaxValue: 2022-12-17T23:55:44Z DEBUG 1382999999 2022-12-17T23:55:44Z DEBUG dnaNextValue: 2022-12-17T23:55:44Z DEBUG 1382800000 2022-12-17T23:55:44Z DEBUG dnaScope: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG dnaSharedCfgDN: 2022-12-17T23:55:44Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG dnaThreshold: 2022-12-17T23:55:44Z DEBUG 500 2022-12-17T23:55:44Z DEBUG dnaType: 2022-12-17T23:55:44Z DEBUG uidNumber 2022-12-17T23:55:44Z DEBUG gidNumber 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/62-ranges.update 0.013 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/71-idviews-sasl-mapping.update' 2022-12-17T23:55:44Z DEBUG New entry: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ID Overridden Principal 2022-12-17T23:55:44Z DEBUG nsSaslMapBaseDNTemplate: 2022-12-17T23:55:44Z DEBUG cn=default trust view,cn=views,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG nsSaslMapFilterTemplate: 2022-12-17T23:55:44Z DEBUG (&(ipaoriginaluid=\1@\2)(objectclass=ipaUserOverride)) 2022-12-17T23:55:44Z DEBUG nsSaslMapPriority: 2022-12-17T23:55:44Z DEBUG 20 2022-12-17T23:55:44Z DEBUG nsSaslMapRegexString: 2022-12-17T23:55:44Z DEBUG \(.*\)@\(.*\) 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsSaslMapping 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ID Overridden Principal 2022-12-17T23:55:44Z DEBUG nsSaslMapBaseDNTemplate: 2022-12-17T23:55:44Z DEBUG cn=default trust view,cn=views,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG nsSaslMapFilterTemplate: 2022-12-17T23:55:44Z DEBUG (&(ipaoriginaluid=\1@\2)(objectclass=ipaUserOverride)) 2022-12-17T23:55:44Z DEBUG nsSaslMapPriority: 2022-12-17T23:55:44Z DEBUG 20 2022-12-17T23:55:44Z DEBUG nsSaslMapRegexString: 2022-12-17T23:55:44Z DEBUG \(.*\)@\(.*\) 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsSaslMapping 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/71-idviews-sasl-mapping.update 0.012 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/71-idviews.update' 2022-12-17T23:55:44Z DEBUG New entry: cn=views,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=views,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG views 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=views,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG views 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/71-idviews.update 0.005 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/72-domainlevels.update' 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=Domain Level,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=Domain Level,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG ipaDomainLevelConfig 2022-12-17T23:55:44Z DEBUG ipaConfigObject 2022-12-17T23:55:44Z DEBUG ipaDomainLevel: 2022-12-17T23:55:44Z DEBUG 1 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Domain Level 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=Domain Level,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG ipaDomainLevelConfig 2022-12-17T23:55:44Z DEBUG ipaConfigObject 2022-12-17T23:55:44Z DEBUG ipaDomainLevel: 2022-12-17T23:55:44Z DEBUG 1 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Domain Level 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=master.redacted_domain.com,cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=master.redacted_domain.com,cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG ipaReplTopoManagedServer 2022-12-17T23:55:44Z DEBUG ipaConfigObject 2022-12-17T23:55:44Z DEBUG ipaSupportedDomainLevelConfig 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG master.redacted_domain.com 2022-12-17T23:55:44Z DEBUG ipaReplTopoManagedSuffix: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG ipaMinDomainLevel: 2022-12-17T23:55:44Z DEBUG 1 2022-12-17T23:55:44Z DEBUG ipaMaxDomainLevel: 2022-12-17T23:55:44Z DEBUG 1 2022-12-17T23:55:44Z DEBUG add: 'ipaConfigObject' to objectClass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2022-12-17T23:55:44Z DEBUG add: updated value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaSupportedDomainLevelConfig', 'ipaConfigObject'] 2022-12-17T23:55:44Z DEBUG add: 'ipaSupportedDomainLevelConfig' to objectClass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaSupportedDomainLevelConfig', 'ipaConfigObject'] 2022-12-17T23:55:44Z DEBUG add: updated value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2022-12-17T23:55:44Z DEBUG only: set ipaMinDomainLevel to '1', current value ['1'] 2022-12-17T23:55:44Z DEBUG only: updated value ['1'] 2022-12-17T23:55:44Z DEBUG only: set ipaMaxDomainLevel to '1', current value ['1'] 2022-12-17T23:55:44Z DEBUG only: updated value ['1'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=master.redacted_domain.com,cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG ipaReplTopoManagedServer 2022-12-17T23:55:44Z DEBUG ipaConfigObject 2022-12-17T23:55:44Z DEBUG ipaSupportedDomainLevelConfig 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG master.redacted_domain.com 2022-12-17T23:55:44Z DEBUG ipaReplTopoManagedSuffix: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG ipaMinDomainLevel: 2022-12-17T23:55:44Z DEBUG 1 2022-12-17T23:55:44Z DEBUG ipaMaxDomainLevel: 2022-12-17T23:55:44Z DEBUG 1 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/72-domainlevels.update 0.007 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/73-certmap.update' 2022-12-17T23:55:44Z DEBUG New entry: cn=certmap,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=certmap,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectclass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG ipaCertMapConfigObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG certmap 2022-12-17T23:55:44Z DEBUG ipaCertMapPromptUsername: 2022-12-17T23:55:44Z DEBUG FALSE 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=certmap,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectclass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG ipaCertMapConfigObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG certmap 2022-12-17T23:55:44Z DEBUG ipaCertMapPromptUsername: 2022-12-17T23:55:44Z DEBUG FALSE 2022-12-17T23:55:44Z DEBUG New entry: cn=certmaprules,cn=certmap,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=certmaprules,cn=certmap,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectclass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG certmaprules 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=certmaprules,cn=certmap,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectclass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG certmaprules 2022-12-17T23:55:44Z DEBUG New entry: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Certificate Identity Mapping Administrators 2022-12-17T23:55:44Z DEBUG description: 2022-12-17T23:55:44Z DEBUG Certificate Identity Mapping Administrators 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Certificate Identity Mapping Administrators 2022-12-17T23:55:44Z DEBUG description: 2022-12-17T23:55:44Z DEBUG Certificate Identity Mapping Administrators 2022-12-17T23:55:44Z DEBUG Updating existing entry: dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG domain 2022-12-17T23:55:44Z DEBUG pilotObject 2022-12-17T23:55:44Z DEBUG domainRelatedObject 2022-12-17T23:55:44Z DEBUG nisDomainObject 2022-12-17T23:55:44Z DEBUG dc: 2022-12-17T23:55:44Z DEBUG redacted_domain 2022-12-17T23:55:44Z DEBUG info: 2022-12-17T23:55:44Z DEBUG IPA V2.0 2022-12-17T23:55:44Z DEBUG associatedDomain: 2022-12-17T23:55:44Z DEBUG redacted_domain.com 2022-12-17T23:55:44Z DEBUG nisDomain: 2022-12-17T23:55:44Z DEBUG redacted_domain.com 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:44Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:44Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:44Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:44Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG add: '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG domain 2022-12-17T23:55:44Z DEBUG pilotObject 2022-12-17T23:55:44Z DEBUG domainRelatedObject 2022-12-17T23:55:44Z DEBUG nisDomainObject 2022-12-17T23:55:44Z DEBUG dc: 2022-12-17T23:55:44Z DEBUG redacted_domain 2022-12-17T23:55:44Z DEBUG info: 2022-12-17T23:55:44Z DEBUG IPA V2.0 2022-12-17T23:55:44Z DEBUG associatedDomain: 2022-12-17T23:55:44Z DEBUG redacted_domain.com 2022-12-17T23:55:44Z DEBUG nisDomain: 2022-12-17T23:55:44Z DEBUG redacted_domain.com 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2022-12-17T23:55:44Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=redacted_domain,dc=com")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2022-12-17T23:55:44Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:44Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:44Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2022-12-17T23:55:44Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2022-12-17T23:55:44Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=redacted_domain,dc=com" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=redacted_domain,dc=com" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:44Z DEBUG [(0, 'aci', ['(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-certmap.update 0.025 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/73-custodia.update' 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG custodia 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG custodia 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG dogtag 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG dogtag 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-custodia.update 0.004 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/73-subid.update' 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG MemberOf Plugin 2022-12-17T23:55:44Z DEBUG memberofattr: 2022-12-17T23:55:44Z DEBUG memberOf 2022-12-17T23:55:44Z DEBUG memberofgroupattr: 2022-12-17T23:55:44Z DEBUG member 2022-12-17T23:55:44Z DEBUG memberUser 2022-12-17T23:55:44Z DEBUG memberHost 2022-12-17T23:55:44Z DEBUG ipaOwner 2022-12-17T23:55:44Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:44Z DEBUG database 2022-12-17T23:55:44Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:44Z DEBUG memberof plugin 2022-12-17T23:55:44Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:44Z DEBUG on 2022-12-17T23:55:44Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:44Z DEBUG memberof 2022-12-17T23:55:44Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:44Z DEBUG memberof_postop_init 2022-12-17T23:55:44Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:44Z DEBUG libmemberof-plugin 2022-12-17T23:55:44Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:44Z DEBUG betxnpostoperation 2022-12-17T23:55:44Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:44Z DEBUG 389 Project 2022-12-17T23:55:44Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:44Z DEBUG 2.2.4 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsSlapdPlugin 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG memberofentryscopeexcludesubtree: 2022-12-17T23:55:44Z DEBUG cn=compat,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG memberofentryscope: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG add: 'ipaOwner' to memberofgroupattr, current value ['member', 'memberUser', 'memberHost', 'ipaOwner'] 2022-12-17T23:55:44Z DEBUG add: updated value ['member', 'memberUser', 'memberHost', 'ipaOwner'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG MemberOf Plugin 2022-12-17T23:55:44Z DEBUG memberofattr: 2022-12-17T23:55:44Z DEBUG memberOf 2022-12-17T23:55:44Z DEBUG memberofgroupattr: 2022-12-17T23:55:44Z DEBUG member 2022-12-17T23:55:44Z DEBUG memberUser 2022-12-17T23:55:44Z DEBUG memberHost 2022-12-17T23:55:44Z DEBUG ipaOwner 2022-12-17T23:55:44Z DEBUG nsslapd-plugin-depends-on-type: 2022-12-17T23:55:44Z DEBUG database 2022-12-17T23:55:44Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:44Z DEBUG memberof plugin 2022-12-17T23:55:44Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:44Z DEBUG on 2022-12-17T23:55:44Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:44Z DEBUG memberof 2022-12-17T23:55:44Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:44Z DEBUG memberof_postop_init 2022-12-17T23:55:44Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:44Z DEBUG libmemberof-plugin 2022-12-17T23:55:44Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:44Z DEBUG betxnpostoperation 2022-12-17T23:55:44Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:44Z DEBUG 389 Project 2022-12-17T23:55:44Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:44Z DEBUG 2.2.4 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsSlapdPlugin 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG memberofentryscopeexcludesubtree: 2022-12-17T23:55:44Z DEBUG cn=compat,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG memberofentryscope: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG New entry: cn=subids,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=subids,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG subids 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=subids,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG subids 2022-12-17T23:55:44Z DEBUG New entry: cn=Subordinate ID Selfservice User,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=Subordinate ID Selfservice User,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Subordinate ID Selfservice User 2022-12-17T23:55:44Z DEBUG description: 2022-12-17T23:55:44Z DEBUG User that can self-request subordiante ids 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=Subordinate ID Selfservice User,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Subordinate ID Selfservice User 2022-12-17T23:55:44Z DEBUG description: 2022-12-17T23:55:44Z DEBUG User that can self-request subordiante ids 2022-12-17T23:55:44Z DEBUG New entry: cn=Subordinate ID Selfservice Users,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=Subordinate ID Selfservice Users,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Subordinate ID Selfservice Users 2022-12-17T23:55:44Z DEBUG description: 2022-12-17T23:55:44Z DEBUG Subordinate ID Selfservice User 2022-12-17T23:55:44Z DEBUG member: 2022-12-17T23:55:44Z DEBUG cn=Subordinate ID Selfservice User,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=Subordinate ID Selfservice Users,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Subordinate ID Selfservice Users 2022-12-17T23:55:44Z DEBUG description: 2022-12-17T23:55:44Z DEBUG Subordinate ID Selfservice User 2022-12-17T23:55:44Z DEBUG member: 2022-12-17T23:55:44Z DEBUG cn=Subordinate ID Selfservice User,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG New entry: cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG ipapermission 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Self-service subordinate ID 2022-12-17T23:55:44Z DEBUG ipapermissiontype: 2022-12-17T23:55:44Z DEBUG SYSTEM 2022-12-17T23:55:44Z DEBUG member: 2022-12-17T23:55:44Z DEBUG cn=Subordinate ID Selfservice Users,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG ipapermission 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Self-service subordinate ID 2022-12-17T23:55:44Z DEBUG ipapermissiontype: 2022-12-17T23:55:44Z DEBUG SYSTEM 2022-12-17T23:55:44Z DEBUG member: 2022-12-17T23:55:44Z DEBUG cn=Subordinate ID Selfservice Users,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG New entry: cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Subordinate ID Administrators 2022-12-17T23:55:44Z DEBUG description: 2022-12-17T23:55:44Z DEBUG Subordinate ID Administrators 2022-12-17T23:55:44Z DEBUG member: 2022-12-17T23:55:44Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG nestedgroup 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Subordinate ID Administrators 2022-12-17T23:55:44Z DEBUG description: 2022-12-17T23:55:44Z DEBUG Subordinate ID Administrators 2022-12-17T23:55:44Z DEBUG member: 2022-12-17T23:55:44Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG New entry: cn=Manage subordinate ID,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=Manage subordinate ID,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG ipapermission 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Manage subordinate ID 2022-12-17T23:55:44Z DEBUG ipapermissiontype: 2022-12-17T23:55:44Z DEBUG SYSTEM 2022-12-17T23:55:44Z DEBUG member: 2022-12-17T23:55:44Z DEBUG cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=Manage subordinate ID,cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG groupofnames 2022-12-17T23:55:44Z DEBUG ipapermission 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Manage subordinate ID 2022-12-17T23:55:44Z DEBUG ipapermissiontype: 2022-12-17T23:55:44Z DEBUG SYSTEM 2022-12-17T23:55:44Z DEBUG member: 2022-12-17T23:55:44Z DEBUG cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=subids,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=subids,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG subids 2022-12-17T23:55:44Z DEBUG add: '(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(ipasubuidnumber=-1) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(ipasubgidnumber=-1) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "selfservice: Add subordinate id";allow (add, write) userattr = "ipaowner#SELFDN" and groupdn="ldap:///cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(ipasubuidnumber=-1) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(ipasubgidnumber=-1) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "selfservice: Add subordinate id";allow (add, write) userattr = "ipaowner#SELFDN" and groupdn="ldap:///cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG add: '(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(|(ipasubuidnumber>=1)(ipasubuidnumber=-1)) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(|(ipasubgidnumber>=1)(ipasubgidnumber=-1)) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "Add subordinate ids to any user";allow (add, write) groupdn="ldap:///cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(ipasubuidnumber=-1) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(ipasubgidnumber=-1) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "selfservice: Add subordinate id";allow (add, write) userattr = "ipaowner#SELFDN" and groupdn="ldap:///cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(ipasubuidnumber=-1) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(ipasubgidnumber=-1) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "selfservice: Add subordinate id";allow (add, write) userattr = "ipaowner#SELFDN" and groupdn="ldap:///cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(|(ipasubuidnumber>=1)(ipasubuidnumber=-1)) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(|(ipasubgidnumber>=1)(ipasubgidnumber=-1)) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "Add subordinate ids to any user";allow (add, write) groupdn="ldap:///cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=subids,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG subids 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(ipasubuidnumber=-1) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(ipasubgidnumber=-1) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "selfservice: Add subordinate id";allow (add, write) userattr = "ipaowner#SELFDN" and groupdn="ldap:///cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(|(ipasubuidnumber>=1)(ipasubuidnumber=-1)) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(|(ipasubgidnumber>=1)(ipasubgidnumber=-1)) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "Add subordinate ids to any user";allow (add, write) groupdn="ldap:///cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG [(2, 'aci', ['(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(ipasubuidnumber=-1) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(ipasubgidnumber=-1) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "selfservice: Add subordinate id";allow (add, write) userattr = "ipaowner#SELFDN" and groupdn="ldap:///cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(|(ipasubuidnumber>=1)(ipasubuidnumber=-1)) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(|(ipasubgidnumber>=1)(ipasubgidnumber=-1)) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "Add subordinate ids to any user";allow (add, write) groupdn="ldap:///cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(ipasubuidnumber=-1) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(ipasubgidnumber=-1) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "selfservice: Add subordinate id";allow (add, write) userattr = "ipaowner#SELFDN" and groupdn="ldap:///cn=Self-service subordinate ID,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', b'(targetfilter = "(objectclass=ipasubordinateidentry)")(targetattr="description || ipaowner || ipauniqueid")(targattrfilters = "add=objectClass:(|(objectClass=top)(objectClass=ipasubordinateid)(objectClass=ipasubordinateidentry)(objectClass=ipasubordinategid)(objectClass=ipasubordinateuid)) && ipasubuidnumber:(|(ipasubuidnumber>=1)(ipasubuidnumber=-1)) && ipasubuidcount:(ipasubuidcount=65536) && ipasubgidnumber:(|(ipasubgidnumber>=1)(ipasubgidnumber=-1)) && ipasubgidcount:(ipasubgidcount=65536), del=ipasubuidnumber:(!(ipasubuidnumber=*)) && ipasubuidcount:(!(ipasubuidcount=*)) && ipasubgidnumber:(!(ipasubgidnumber=*)) && ipasubgidcount:(!(ipasubgidcount=*))")(version 3.0;acl "Add subordinate ids to any user";allow (add, write) groupdn="ldap:///cn=Subordinate ID Administrators,cn=privileges,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG subordinate-ids 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG subordinate-ids 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=Subordinate IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=Subordinate IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Subordinate IDs 2022-12-17T23:55:44Z DEBUG dnaExcludeScope: 2022-12-17T23:55:44Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG dnaFilter: 2022-12-17T23:55:44Z DEBUG (objectClass=ipaSubordinateId) 2022-12-17T23:55:44Z DEBUG dnaInterval: 2022-12-17T23:55:44Z DEBUG 65536 2022-12-17T23:55:44Z DEBUG dnaMagicRegen: 2022-12-17T23:55:44Z DEBUG -1 2022-12-17T23:55:44Z DEBUG dnaMaxValue: 2022-12-17T23:55:44Z DEBUG 4294836224 2022-12-17T23:55:44Z DEBUG dnaNextValue: 2022-12-17T23:55:44Z DEBUG 2147483648 2022-12-17T23:55:44Z DEBUG dnaScope: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG dnaSharedCfgDN: 2022-12-17T23:55:44Z DEBUG cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG dnaThreshold: 2022-12-17T23:55:44Z DEBUG 500 2022-12-17T23:55:44Z DEBUG dnaType: 2022-12-17T23:55:44Z DEBUG ipasubuidnumber 2022-12-17T23:55:44Z DEBUG ipasubgidnumber 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG add: '(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG add: '(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to aci, current value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=Subordinate IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Subordinate IDs 2022-12-17T23:55:44Z DEBUG dnaExcludeScope: 2022-12-17T23:55:44Z DEBUG cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG dnaFilter: 2022-12-17T23:55:44Z DEBUG (objectClass=ipaSubordinateId) 2022-12-17T23:55:44Z DEBUG dnaInterval: 2022-12-17T23:55:44Z DEBUG 65536 2022-12-17T23:55:44Z DEBUG dnaMagicRegen: 2022-12-17T23:55:44Z DEBUG -1 2022-12-17T23:55:44Z DEBUG dnaMaxValue: 2022-12-17T23:55:44Z DEBUG 4294836224 2022-12-17T23:55:44Z DEBUG dnaNextValue: 2022-12-17T23:55:44Z DEBUG 2147483648 2022-12-17T23:55:44Z DEBUG dnaScope: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG dnaSharedCfgDN: 2022-12-17T23:55:44Z DEBUG cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG dnaThreshold: 2022-12-17T23:55:44Z DEBUG 500 2022-12-17T23:55:44Z DEBUG dnaType: 2022-12-17T23:55:44Z DEBUG ipasubuidnumber 2022-12-17T23:55:44Z DEBUG ipasubgidnumber 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG [(2, 'aci', ['(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', '(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)', b'(targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=REDACTED_DOMAIN.COM_subid_range,cn=ranges,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=REDACTED_DOMAIN.COM_subid_range,cn=ranges,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG ipaIDrange 2022-12-17T23:55:44Z DEBUG ipaTrustedADDomainRange 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG REDACTED_DOMAIN.COM_subid_range 2022-12-17T23:55:44Z DEBUG ipaBaseID: 2022-12-17T23:55:44Z DEBUG 2147483648 2022-12-17T23:55:44Z DEBUG ipaIDRangeSize: 2022-12-17T23:55:44Z DEBUG 2147352576 2022-12-17T23:55:44Z DEBUG ipaBaseRID: 2022-12-17T23:55:44Z DEBUG 2147283648 2022-12-17T23:55:44Z DEBUG ipaNTTrustedDomainSID: 2022-12-17T23:55:44Z DEBUG S-1-5-21-738065-838566-2100256441 2022-12-17T23:55:44Z DEBUG ipaRangeType: 2022-12-17T23:55:44Z DEBUG ipa-ad-trust 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=REDACTED_DOMAIN.COM_subid_range,cn=ranges,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG ipaIDrange 2022-12-17T23:55:44Z DEBUG ipaTrustedADDomainRange 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG REDACTED_DOMAIN.COM_subid_range 2022-12-17T23:55:44Z DEBUG ipaBaseID: 2022-12-17T23:55:44Z DEBUG 2147483648 2022-12-17T23:55:44Z DEBUG ipaIDRangeSize: 2022-12-17T23:55:44Z DEBUG 2147352576 2022-12-17T23:55:44Z DEBUG ipaBaseRID: 2022-12-17T23:55:44Z DEBUG 2147283648 2022-12-17T23:55:44Z DEBUG ipaNTTrustedDomainSID: 2022-12-17T23:55:44Z DEBUG S-1-5-21-738065-838566-2100256441 2022-12-17T23:55:44Z DEBUG ipaRangeType: 2022-12-17T23:55:44Z DEBUG ipa-ad-trust 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-subid.update 0.196 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/73-winsync.update' 2022-12-17T23:55:44Z DEBUG New entry: uid=passsync,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: uid=passsync,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG addifexist: 'inetUser' to objectClass, current value [] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: uid=passsync,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-winsync.update 0.001 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/75-user-trust-attributes.update' 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG users 2022-12-17T23:55:44Z DEBUG add: '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)' to aci, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG add: '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)'] 2022-12-17T23:55:44Z DEBUG add: updated value ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsContainer 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG users 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";) 2022-12-17T23:55:44Z DEBUG (targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";) 2022-12-17T23:55:44Z DEBUG [(2, 'aci', ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com";)', b'(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/75-user-trust-attributes.update 0.005 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/80-schema_compat.update' 2022-12-17T23:55:44Z DEBUG New entry: cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectclass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsSlapdPlugin 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Schema Compatibility 2022-12-17T23:55:44Z DEBUG nsslapd-pluginpath: 2022-12-17T23:55:44Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2022-12-17T23:55:44Z DEBUG nsslapd-plugininitfunc: 2022-12-17T23:55:44Z DEBUG schema_compat_plugin_init 2022-12-17T23:55:44Z DEBUG nsslapd-plugintype: 2022-12-17T23:55:44Z DEBUG object 2022-12-17T23:55:44Z DEBUG nsslapd-pluginenabled: 2022-12-17T23:55:44Z DEBUG on 2022-12-17T23:55:44Z DEBUG nsslapd-pluginid: 2022-12-17T23:55:44Z DEBUG schema-compat-plugin 2022-12-17T23:55:44Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:44Z DEBUG 40 2022-12-17T23:55:44Z DEBUG nsslapd-pluginversion: 2022-12-17T23:55:44Z DEBUG 0.8 2022-12-17T23:55:44Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:44Z DEBUG on 2022-12-17T23:55:44Z DEBUG nsslapd-pluginvendor: 2022-12-17T23:55:44Z DEBUG redhat.com 2022-12-17T23:55:44Z DEBUG nsslapd-plugindescription: 2022-12-17T23:55:44Z DEBUG Schema Compatibility Plugin 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectclass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsSlapdPlugin 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Schema Compatibility 2022-12-17T23:55:44Z DEBUG nsslapd-pluginpath: 2022-12-17T23:55:44Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2022-12-17T23:55:44Z DEBUG nsslapd-plugininitfunc: 2022-12-17T23:55:44Z DEBUG schema_compat_plugin_init 2022-12-17T23:55:44Z DEBUG nsslapd-plugintype: 2022-12-17T23:55:44Z DEBUG object 2022-12-17T23:55:44Z DEBUG nsslapd-pluginenabled: 2022-12-17T23:55:44Z DEBUG on 2022-12-17T23:55:44Z DEBUG nsslapd-pluginid: 2022-12-17T23:55:44Z DEBUG schema-compat-plugin 2022-12-17T23:55:44Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:44Z DEBUG 40 2022-12-17T23:55:44Z DEBUG nsslapd-pluginversion: 2022-12-17T23:55:44Z DEBUG 0.8 2022-12-17T23:55:44Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:44Z DEBUG on 2022-12-17T23:55:44Z DEBUG nsslapd-pluginvendor: 2022-12-17T23:55:44Z DEBUG redhat.com 2022-12-17T23:55:44Z DEBUG nsslapd-plugindescription: 2022-12-17T23:55:44Z DEBUG Schema Compatibility Plugin 2022-12-17T23:55:44Z DEBUG New entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG users 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=users 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=users, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG uid=%{uid} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG gecos=%{cn} 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG uidNumber=%{uidNumber} 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG loginShell=%{loginShell} 2022-12-17T23:55:44Z DEBUG homeDirectory=%{homeDirectory} 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG users 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=users 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=users, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG uid=%{uid} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG gecos=%{cn} 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG uidNumber=%{uidNumber} 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG loginShell=%{loginShell} 2022-12-17T23:55:44Z DEBUG homeDirectory=%{homeDirectory} 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG New entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG groups 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=groups 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=groups, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG memberUid=%{memberUid} 2022-12-17T23:55:44Z DEBUG memberUid=%deref_r("member","uid") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG groups 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=groups 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=groups, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG memberUid=%{memberUid} 2022-12-17T23:55:44Z DEBUG memberUid=%deref_r("member","uid") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG New entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG add: 'top' to objectClass, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['top'] 2022-12-17T23:55:44Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2022-12-17T23:55:44Z DEBUG add: updated value ['top', 'extensibleObject'] 2022-12-17T23:55:44Z DEBUG add: 'ng' to cn, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['ng'] 2022-12-17T23:55:44Z DEBUG add: 'cn=compat, dc=redacted_domain,dc=com' to schema-compat-container-group, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=compat, dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: 'cn=ng' to schema-compat-container-rdn, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=ng'] 2022-12-17T23:55:44Z DEBUG add: 'yes' to schema-compat-check-access, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['yes'] 2022-12-17T23:55:44Z DEBUG add: 'cn=ng, cn=alt, dc=redacted_domain,dc=com' to schema-compat-search-base, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=ng, cn=alt, dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: '(objectclass=ipaNisNetgroup)' to schema-compat-search-filter, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['(objectclass=ipaNisNetgroup)'] 2022-12-17T23:55:44Z DEBUG add: 'cn=%{cn}' to schema-compat-entry-rdn, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=%{cn}'] 2022-12-17T23:55:44Z DEBUG add: 'objectclass=nisNetgroup' to schema-compat-entry-attribute, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=nisNetgroup'] 2022-12-17T23:55:44Z DEBUG add: 'memberNisNetgroup=%deref_r("member","cn")' to schema-compat-entry-attribute, current value ['objectclass=nisNetgroup'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")'] 2022-12-17T23:55:44Z DEBUG add: 'nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-})' to schema-compat-entry-attribute, current value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")', 'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ng 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=ng 2022-12-17T23:55:44Z DEBUG schema-compat-check-access: 2022-12-17T23:55:44Z DEBUG yes 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=ng, cn=alt, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG (objectclass=ipaNisNetgroup) 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=nisNetgroup 2022-12-17T23:55:44Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2022-12-17T23:55:44Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) 2022-12-17T23:55:44Z DEBUG New entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG add: 'top' to objectClass, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['top'] 2022-12-17T23:55:44Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2022-12-17T23:55:44Z DEBUG add: updated value ['top', 'extensibleObject'] 2022-12-17T23:55:44Z DEBUG add: 'sudoers' to cn, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['sudoers'] 2022-12-17T23:55:44Z DEBUG add: 'ou=SUDOers, dc=redacted_domain,dc=com' to schema-compat-container-group, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['ou=SUDOers, dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: 'cn=sudorules, cn=sudo, dc=redacted_domain,dc=com' to schema-compat-search-base, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=sudorules, cn=sudo, dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: '(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))' to schema-compat-search-filter, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))'] 2022-12-17T23:55:44Z DEBUG add: '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")' to schema-compat-entry-rdn, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2022-12-17T23:55:44Z DEBUG add: 'objectclass=sudoRole' to schema-compat-entry-attribute, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole'] 2022-12-17T23:55:44Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoOption=%{ipaSudoOpt}' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG sudoers 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG ou=SUDOers, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=sudorules, cn=sudo, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=sudoRole 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2022-12-17T23:55:44Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2022-12-17T23:55:44Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoOption=%{ipaSudoOpt} 2022-12-17T23:55:44Z DEBUG New entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG computers 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=computers 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=computers, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%first("%{fqdn}") 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=device 2022-12-17T23:55:44Z DEBUG objectclass=ieee802Device 2022-12-17T23:55:44Z DEBUG cn=%{fqdn} 2022-12-17T23:55:44Z DEBUG macAddress=%{macAddress} 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG computers 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=computers 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=computers, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%first("%{fqdn}") 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=device 2022-12-17T23:55:44Z DEBUG objectclass=ieee802Device 2022-12-17T23:55:44Z DEBUG cn=%{fqdn} 2022-12-17T23:55:44Z DEBUG macAddress=%{macAddress} 2022-12-17T23:55:44Z DEBUG Updating existing entry: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG VLV Request Control 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG directoryServerFeature 2022-12-17T23:55:44Z DEBUG oid: 2022-12-17T23:55:44Z DEBUG 2.16.840.1.113730.3.4.9 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";) 2022-12-17T23:55:44Z DEBUG only: set aci to '(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )', current value ['(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)'] 2022-12-17T23:55:44Z DEBUG only: updated value ['(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG VLV Request Control 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG directoryServerFeature 2022-12-17T23:55:44Z DEBUG oid: 2022-12-17T23:55:44Z DEBUG 2.16.840.1.113730.3.4.9 2022-12-17T23:55:44Z DEBUG aci: 2022-12-17T23:55:44Z DEBUG (targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; ) 2022-12-17T23:55:44Z DEBUG [(1, 'aci', ['(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)']), (0, 'aci', ['(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(1, 'aci', [b'(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)']), (0, 'aci', [b'(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG sudoers 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG ou=SUDOers, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=sudorules, cn=sudo, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=sudoRole 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2022-12-17T23:55:44Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2022-12-17T23:55:44Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoOption=%{ipaSudoOpt} 2022-12-17T23:55:44Z DEBUG only: set schema-compat-entry-rdn to '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")', current value ['%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2022-12-17T23:55:44Z DEBUG only: updated value ['%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2022-12-17T23:55:44Z DEBUG remove: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2022-12-17T23:55:44Z DEBUG remove: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' not in schema-compat-entry-attribute 2022-12-17T23:55:44Z DEBUG remove: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2022-12-17T23:55:44Z DEBUG remove: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' not in schema-compat-entry-attribute 2022-12-17T23:55:44Z DEBUG remove: 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2022-12-17T23:55:44Z DEBUG remove: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2022-12-17T23:55:44Z DEBUG remove: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2022-12-17T23:55:44Z DEBUG remove: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' not in schema-compat-entry-attribute 2022-12-17T23:55:44Z DEBUG remove: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2022-12-17T23:55:44Z DEBUG remove: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' not in schema-compat-entry-attribute 2022-12-17T23:55:44Z DEBUG remove: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2022-12-17T23:55:44Z DEBUG remove: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' not in schema-compat-entry-attribute 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG sudoers 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG ou=SUDOers, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=sudorules, cn=sudo, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=sudoRole 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2022-12-17T23:55:44Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoOption=%{ipaSudoOpt} 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG sudoers 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG ou=SUDOers, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=sudorules, cn=sudo, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=sudoRole 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2022-12-17T23:55:44Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2022-12-17T23:55:44Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoOption=%{ipaSudoOpt} 2022-12-17T23:55:44Z DEBUG add: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2022-12-17T23:55:44Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2022-12-17T23:55:44Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2022-12-17T23:55:44Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2022-12-17T23:55:44Z DEBUG add: 'dc=redacted_domain,dc=com' to schema-compat-restrict-subtree, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: updated value ['dc=redacted_domain,dc=com', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2022-12-17T23:55:44Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com' to schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG sudoers 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG ou=SUDOers, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=sudorules, cn=sudo, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=sudoRole 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2022-12-17T23:55:44Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2022-12-17T23:55:44Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoOption=%{ipaSudoOpt} 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com']), (0, 'schema-compat-entry-attribute', ['sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")']), (2, 'schema-compat-restrict-subtree', ['dc=redacted_domain,dc=com', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(2, 'schema-compat-ignore-subtree', [b'cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', b'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com']), (0, 'schema-compat-entry-attribute', [b'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")']), (2, 'schema-compat-restrict-subtree', [b'dc=redacted_domain,dc=com', b'cn=Schema Compatibility,cn=plugins,cn=config'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ng 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=ng 2022-12-17T23:55:44Z DEBUG schema-compat-check-access: 2022-12-17T23:55:44Z DEBUG yes 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=ng, cn=alt, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG (objectclass=ipaNisNetgroup) 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=nisNetgroup 2022-12-17T23:55:44Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2022-12-17T23:55:44Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) 2022-12-17T23:55:44Z DEBUG replace: updated value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")', 'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})'] 2022-12-17T23:55:44Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2022-12-17T23:55:44Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2022-12-17T23:55:44Z DEBUG add: 'dc=redacted_domain,dc=com' to schema-compat-restrict-subtree, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: updated value ['dc=redacted_domain,dc=com', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2022-12-17T23:55:44Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com' to schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG ng 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=ng 2022-12-17T23:55:44Z DEBUG schema-compat-check-access: 2022-12-17T23:55:44Z DEBUG yes 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=ng, cn=alt, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG (objectclass=ipaNisNetgroup) 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=nisNetgroup 2022-12-17T23:55:44Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2022-12-17T23:55:44Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com']), (1, 'schema-compat-entry-attribute', ['nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})']), (0, 'schema-compat-entry-attribute', ['nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})']), (2, 'schema-compat-restrict-subtree', ['dc=redacted_domain,dc=com', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(2, 'schema-compat-ignore-subtree', [b'cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', b'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com']), (1, 'schema-compat-entry-attribute', [b'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})']), (0, 'schema-compat-entry-attribute', [b'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})']), (2, 'schema-compat-restrict-subtree', [b'dc=redacted_domain,dc=com', b'cn=Schema Compatibility,cn=plugins,cn=config'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG computers 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=computers 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=computers, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%first("%{fqdn}") 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=device 2022-12-17T23:55:44Z DEBUG objectclass=ieee802Device 2022-12-17T23:55:44Z DEBUG cn=%{fqdn} 2022-12-17T23:55:44Z DEBUG macAddress=%{macAddress} 2022-12-17T23:55:44Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2022-12-17T23:55:44Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2022-12-17T23:55:44Z DEBUG add: 'dc=redacted_domain,dc=com' to schema-compat-restrict-subtree, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: updated value ['dc=redacted_domain,dc=com', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2022-12-17T23:55:44Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com' to schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG computers 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=computers 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=computers, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%first("%{fqdn}") 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=device 2022-12-17T23:55:44Z DEBUG objectclass=ieee802Device 2022-12-17T23:55:44Z DEBUG cn=%{fqdn} 2022-12-17T23:55:44Z DEBUG macAddress=%{macAddress} 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com']), (2, 'schema-compat-restrict-subtree', ['dc=redacted_domain,dc=com', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(2, 'schema-compat-ignore-subtree', [b'cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', b'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com']), (2, 'schema-compat-restrict-subtree', [b'dc=redacted_domain,dc=com', b'cn=Schema Compatibility,cn=plugins,cn=config'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG sudoers 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG ou=SUDOers, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=sudorules, cn=sudo, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=sudoRole 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2022-12-17T23:55:44Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2022-12-17T23:55:44Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoOption=%{ipaSudoOpt} 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG add: 'sudoOrder=%{sudoOrder}' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoOrder=%{sudoOrder}'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG sudoers 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG ou=SUDOers, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=sudorules, cn=sudo, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=sudoRole 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2022-12-17T23:55:44Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2022-12-17T23:55:44Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2022-12-17T23:55:44Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2022-12-17T23:55:44Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2022-12-17T23:55:44Z DEBUG sudoOption=%{ipaSudoOpt} 2022-12-17T23:55:44Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2022-12-17T23:55:44Z DEBUG sudoOrder=%{sudoOrder} 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG [(0, 'schema-compat-entry-attribute', ['sudoOrder=%{sudoOrder}'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(0, 'schema-compat-entry-attribute', [b'sudoOrder=%{sudoOrder}'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG users 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=users 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=users, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG uid=%{uid} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG gecos=%{cn} 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG uidNumber=%{uidNumber} 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG loginShell=%{loginShell} 2022-12-17T23:55:44Z DEBUG homeDirectory=%{homeDirectory} 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2022-12-17T23:55:44Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2022-12-17T23:55:44Z DEBUG add: 'dc=redacted_domain,dc=com' to schema-compat-restrict-subtree, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: updated value ['dc=redacted_domain,dc=com', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2022-12-17T23:55:44Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com' to schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG users 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=users 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=users, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG uid=%{uid} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG gecos=%{cn} 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG uidNumber=%{uidNumber} 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG loginShell=%{loginShell} 2022-12-17T23:55:44Z DEBUG homeDirectory=%{homeDirectory} 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com']), (2, 'schema-compat-restrict-subtree', ['dc=redacted_domain,dc=com', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(2, 'schema-compat-ignore-subtree', [b'cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', b'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com']), (2, 'schema-compat-restrict-subtree', [b'dc=redacted_domain,dc=com', b'cn=Schema Compatibility,cn=plugins,cn=config'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG groups 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=groups 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=groups, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG memberUid=%{memberUid} 2022-12-17T23:55:44Z DEBUG memberUid=%deref_r("member","uid") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2022-12-17T23:55:44Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2022-12-17T23:55:44Z DEBUG add: 'dc=redacted_domain,dc=com' to schema-compat-restrict-subtree, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: updated value ['dc=redacted_domain,dc=com', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2022-12-17T23:55:44Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com' to schema-compat-ignore-subtree, current value [] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG groups 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=groups 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=groups, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG memberUid=%{memberUid} 2022-12-17T23:55:44Z DEBUG memberUid=%deref_r("member","uid") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', 'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com']), (2, 'schema-compat-restrict-subtree', ['dc=redacted_domain,dc=com', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(2, 'schema-compat-ignore-subtree', [b'cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com', b'cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com']), (2, 'schema-compat-restrict-subtree', [b'dc=redacted_domain,dc=com', b'cn=Schema Compatibility,cn=plugins,cn=config'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsSlapdPlugin 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Schema Compatibility 2022-12-17T23:55:44Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:44Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2022-12-17T23:55:44Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:44Z DEBUG schema_compat_plugin_init 2022-12-17T23:55:44Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:44Z DEBUG object 2022-12-17T23:55:44Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:44Z DEBUG on 2022-12-17T23:55:44Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:44Z DEBUG schema-compat-plugin 2022-12-17T23:55:44Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:44Z DEBUG 40 2022-12-17T23:55:44Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:44Z DEBUG 0.8 2022-12-17T23:55:44Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:44Z DEBUG on 2022-12-17T23:55:44Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:44Z DEBUG redhat.com 2022-12-17T23:55:44Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:44Z DEBUG Schema Compatibility Plugin 2022-12-17T23:55:44Z DEBUG add: '40' to nsslapd-pluginprecedence, current value ['40'] 2022-12-17T23:55:44Z DEBUG add: updated value ['40'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG nsSlapdPlugin 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG Schema Compatibility 2022-12-17T23:55:44Z DEBUG nsslapd-pluginPath: 2022-12-17T23:55:44Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2022-12-17T23:55:44Z DEBUG nsslapd-pluginInitfunc: 2022-12-17T23:55:44Z DEBUG schema_compat_plugin_init 2022-12-17T23:55:44Z DEBUG nsslapd-pluginType: 2022-12-17T23:55:44Z DEBUG object 2022-12-17T23:55:44Z DEBUG nsslapd-pluginEnabled: 2022-12-17T23:55:44Z DEBUG on 2022-12-17T23:55:44Z DEBUG nsslapd-pluginId: 2022-12-17T23:55:44Z DEBUG schema-compat-plugin 2022-12-17T23:55:44Z DEBUG nsslapd-pluginprecedence: 2022-12-17T23:55:44Z DEBUG 40 2022-12-17T23:55:44Z DEBUG nsslapd-pluginVersion: 2022-12-17T23:55:44Z DEBUG 0.8 2022-12-17T23:55:44Z DEBUG nsslapd-pluginbetxn: 2022-12-17T23:55:44Z DEBUG on 2022-12-17T23:55:44Z DEBUG nsslapd-pluginVendor: 2022-12-17T23:55:44Z DEBUG redhat.com 2022-12-17T23:55:44Z DEBUG nsslapd-pluginDescription: 2022-12-17T23:55:44Z DEBUG Schema Compatibility Plugin 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG users 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=users 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=users, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG uid=%{uid} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG gecos=%{cn} 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG uidNumber=%{uidNumber} 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG loginShell=%{loginShell} 2022-12-17T23:55:44Z DEBUG homeDirectory=%{homeDirectory} 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2022-12-17T23:55:44Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")'] 2022-12-17T23:55:44Z DEBUG add: 'ipaanchoruuid=%{ipaanchoruuid}' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2022-12-17T23:55:44Z DEBUG add: '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG users 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=users 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=users, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG uid=%{uid} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG gecos=%{cn} 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG uidNumber=%{uidNumber} 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG loginShell=%{loginShell} 2022-12-17T23:55:44Z DEBUG homeDirectory=%{homeDirectory} 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG groups 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=groups 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=groups, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG memberUid=%{memberUid} 2022-12-17T23:55:44Z DEBUG memberUid=%deref_r("member","uid") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2022-12-17T23:55:44Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")'] 2022-12-17T23:55:44Z DEBUG add: 'ipaanchoruuid=%{ipaanchoruuid}' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2022-12-17T23:55:44Z DEBUG add: '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG groups 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=groups 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=groups, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG memberUid=%{memberUid} 2022-12-17T23:55:44Z DEBUG memberUid=%deref_r("member","uid") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG [] 2022-12-17T23:55:44Z DEBUG Updated 0 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG users 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=users 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=users, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG uid=%{uid} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG gecos=%{cn} 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG uidNumber=%{uidNumber} 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG loginShell=%{loginShell} 2022-12-17T23:55:44Z DEBUG homeDirectory=%{homeDirectory} 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG add: 'uid=%{uid}' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2022-12-17T23:55:44Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'uid=%{uid}'] 2022-12-17T23:55:44Z DEBUG replace: updated value ['uid=%first("%{uid}")'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG users 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=users 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=users, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG uid=%first("%{uid}") 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixAccount 2022-12-17T23:55:44Z DEBUG gecos=%{cn} 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG uidNumber=%{uidNumber} 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG loginShell=%{loginShell} 2022-12-17T23:55:44Z DEBUG homeDirectory=%{homeDirectory} 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG uid=%{uid} 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG [(0, 'schema-compat-entry-attribute', ['uid=%{uid}']), (1, 'schema-compat-entry-rdn', ['uid=%{uid}']), (0, 'schema-compat-entry-rdn', ['uid=%first("%{uid}")'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(0, 'schema-compat-entry-attribute', [b'uid=%{uid}']), (1, 'schema-compat-entry-rdn', [b'uid=%{uid}']), (0, 'schema-compat-entry-rdn', [b'uid=%first("%{uid}")'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/80-schema_compat.update 0.216 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/81-externalmembers.update' 2022-12-17T23:55:44Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Initial value 2022-12-17T23:55:44Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG groups 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=groups 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=groups, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG memberUid=%{memberUid} 2022-12-17T23:55:44Z DEBUG memberUid=%deref_r("member","uid") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG addifexist: 'ipaexternalmember=%deref_r("member","ipaexternalmember")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2022-12-17T23:55:44Z DEBUG addifexist: set schema-compat-entry-attribute to ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'ipaexternalmember=%deref_r("member","ipaexternalmember")'] 2022-12-17T23:55:44Z DEBUG addifexist: 'objectclass=ipaexternalgroup' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'ipaexternalmember=%deref_r("member","ipaexternalmember")'] 2022-12-17T23:55:44Z DEBUG addifexist: set schema-compat-entry-attribute to ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'ipaexternalmember=%deref_r("member","ipaexternalmember")', 'objectclass=ipaexternalgroup'] 2022-12-17T23:55:44Z DEBUG --------------------------------------------- 2022-12-17T23:55:44Z DEBUG Final value after applying updates 2022-12-17T23:55:44Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG objectClass: 2022-12-17T23:55:44Z DEBUG top 2022-12-17T23:55:44Z DEBUG extensibleObject 2022-12-17T23:55:44Z DEBUG cn: 2022-12-17T23:55:44Z DEBUG groups 2022-12-17T23:55:44Z DEBUG schema-compat-container-group: 2022-12-17T23:55:44Z DEBUG cn=compat, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-container-rdn: 2022-12-17T23:55:44Z DEBUG cn=groups 2022-12-17T23:55:44Z DEBUG schema-compat-search-base: 2022-12-17T23:55:44Z DEBUG cn=groups, cn=accounts, dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-search-filter: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG schema-compat-entry-rdn: 2022-12-17T23:55:44Z DEBUG cn=%{cn} 2022-12-17T23:55:44Z DEBUG schema-compat-entry-attribute: 2022-12-17T23:55:44Z DEBUG objectclass=posixGroup 2022-12-17T23:55:44Z DEBUG gidNumber=%{gidNumber} 2022-12-17T23:55:44Z DEBUG memberUid=%{memberUid} 2022-12-17T23:55:44Z DEBUG memberUid=%deref_r("member","uid") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:redacted_domain.com:%{ipauniqueid}","") 2022-12-17T23:55:44Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2022-12-17T23:55:44Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2022-12-17T23:55:44Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2022-12-17T23:55:44Z DEBUG objectclass=ipaexternalgroup 2022-12-17T23:55:44Z DEBUG schema-compat-ignore-subtree: 2022-12-17T23:55:44Z DEBUG cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG schema-compat-restrict-subtree: 2022-12-17T23:55:44Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:44Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2022-12-17T23:55:44Z DEBUG [(0, 'schema-compat-entry-attribute', ['ipaexternalmember=%deref_r("member","ipaexternalmember")', 'objectclass=ipaexternalgroup'])] 2022-12-17T23:55:44Z DEBUG Updated 1 2022-12-17T23:55:44Z DEBUG update_entry modlist [(0, 'schema-compat-entry-attribute', [b'ipaexternalmember=%deref_r("member","ipaexternalmember")', b'objectclass=ipaexternalgroup'])] 2022-12-17T23:55:44Z DEBUG Done 2022-12-17T23:55:44Z DEBUG LDAP update duration: /usr/share/ipa/updates/81-externalmembers.update 0.015 sec 2022-12-17T23:55:44Z DEBUG Parsing update file '/usr/share/ipa/updates/90-post_upgrade_plugins.update' 2022-12-17T23:55:44Z DEBUG Executing upgrade plugin: update_ca_topology 2022-12-17T23:55:44Z DEBUG raw: update_ca_topology 2022-12-17T23:55:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:44Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:55:44Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:55:44Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:55:44Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:55:44Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:55:44Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:55:44Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:55:44Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:55:44Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:55:44Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:55:45Z DEBUG Created connection context.ldap2_140472239590864 2022-12-17T23:55:45Z DEBUG raw: idrange_show('REDACTED_DOMAIN.COM_id_range', version='2.251') 2022-12-17T23:55:45Z DEBUG idrange_show('REDACTED_DOMAIN.COM_id_range', rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:55:45Z DEBUG flushing ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:55:45Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:55:45Z DEBUG Parsing update file '/usr/share/ipa/ca-topology.uldif' 2022-12-17T23:55:45Z DEBUG Updating existing entry: cn=master.redacted_domain.com,cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:45Z DEBUG --------------------------------------------- 2022-12-17T23:55:45Z DEBUG Initial value 2022-12-17T23:55:45Z DEBUG dn: cn=master.redacted_domain.com,cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:45Z DEBUG objectClass: 2022-12-17T23:55:45Z DEBUG top 2022-12-17T23:55:45Z DEBUG nsContainer 2022-12-17T23:55:45Z DEBUG ipaReplTopoManagedServer 2022-12-17T23:55:45Z DEBUG ipaConfigObject 2022-12-17T23:55:45Z DEBUG ipaSupportedDomainLevelConfig 2022-12-17T23:55:45Z DEBUG cn: 2022-12-17T23:55:45Z DEBUG master.redacted_domain.com 2022-12-17T23:55:45Z DEBUG ipaReplTopoManagedSuffix: 2022-12-17T23:55:45Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:45Z DEBUG ipaMinDomainLevel: 2022-12-17T23:55:45Z DEBUG 1 2022-12-17T23:55:45Z DEBUG ipaMaxDomainLevel: 2022-12-17T23:55:45Z DEBUG 1 2022-12-17T23:55:45Z DEBUG add: 'ipaReplTopoManagedServer' to objectclass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2022-12-17T23:55:45Z DEBUG add: updated value ['top', 'nsContainer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig', 'ipaReplTopoManagedServer'] 2022-12-17T23:55:45Z DEBUG add: 'o=ipaca' to ipaReplTopoManagedSuffix, current value ['dc=redacted_domain,dc=com'] 2022-12-17T23:55:45Z DEBUG add: updated value ['dc=redacted_domain,dc=com', 'o=ipaca'] 2022-12-17T23:55:45Z DEBUG --------------------------------------------- 2022-12-17T23:55:45Z DEBUG Final value after applying updates 2022-12-17T23:55:45Z DEBUG dn: cn=master.redacted_domain.com,cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:45Z DEBUG objectClass: 2022-12-17T23:55:45Z DEBUG top 2022-12-17T23:55:45Z DEBUG nsContainer 2022-12-17T23:55:45Z DEBUG ipaConfigObject 2022-12-17T23:55:45Z DEBUG ipaSupportedDomainLevelConfig 2022-12-17T23:55:45Z DEBUG ipaReplTopoManagedServer 2022-12-17T23:55:45Z DEBUG cn: 2022-12-17T23:55:45Z DEBUG master.redacted_domain.com 2022-12-17T23:55:45Z DEBUG ipaReplTopoManagedSuffix: 2022-12-17T23:55:45Z DEBUG dc=redacted_domain,dc=com 2022-12-17T23:55:45Z DEBUG o=ipaca 2022-12-17T23:55:45Z DEBUG ipaMinDomainLevel: 2022-12-17T23:55:45Z DEBUG 1 2022-12-17T23:55:45Z DEBUG ipaMaxDomainLevel: 2022-12-17T23:55:45Z DEBUG 1 2022-12-17T23:55:45Z DEBUG [(0, 'ipaReplTopoManagedSuffix', ['o=ipaca'])] 2022-12-17T23:55:45Z DEBUG Updated 1 2022-12-17T23:55:45Z DEBUG update_entry modlist [(0, 'ipaReplTopoManagedSuffix', [b'o=ipaca'])] 2022-12-17T23:55:45Z DEBUG Done 2022-12-17T23:55:45Z DEBUG New entry: cn=ca,cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:45Z DEBUG --------------------------------------------- 2022-12-17T23:55:45Z DEBUG Initial value 2022-12-17T23:55:45Z DEBUG dn: cn=ca,cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:45Z DEBUG objectclass: 2022-12-17T23:55:45Z DEBUG top 2022-12-17T23:55:45Z DEBUG iparepltopoconf 2022-12-17T23:55:45Z DEBUG ipaReplTopoConfRoot: 2022-12-17T23:55:45Z DEBUG o=ipaca 2022-12-17T23:55:45Z DEBUG cn: 2022-12-17T23:55:45Z DEBUG ca 2022-12-17T23:55:45Z DEBUG --------------------------------------------- 2022-12-17T23:55:45Z DEBUG Final value after applying updates 2022-12-17T23:55:45Z DEBUG dn: cn=ca,cn=topology,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:45Z DEBUG objectclass: 2022-12-17T23:55:45Z DEBUG top 2022-12-17T23:55:45Z DEBUG iparepltopoconf 2022-12-17T23:55:45Z DEBUG ipaReplTopoConfRoot: 2022-12-17T23:55:45Z DEBUG o=ipaca 2022-12-17T23:55:45Z DEBUG cn: 2022-12-17T23:55:45Z DEBUG ca 2022-12-17T23:55:45Z DEBUG New entry: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2022-12-17T23:55:45Z DEBUG --------------------------------------------- 2022-12-17T23:55:45Z DEBUG Initial value 2022-12-17T23:55:45Z DEBUG dn: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2022-12-17T23:55:45Z DEBUG onlyifexist: 'cn=replication managers,cn=sysaccounts,cn=etc,dc=redacted_domain,dc=com' to nsds5replicabinddngroup, current value [] 2022-12-17T23:55:45Z DEBUG --------------------------------------------- 2022-12-17T23:55:45Z DEBUG Final value after applying updates 2022-12-17T23:55:45Z DEBUG dn: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2022-12-17T23:55:45Z DEBUG LDAP update duration: /usr/share/ipa/ca-topology.uldif 0.012 sec 2022-12-17T23:55:45Z DEBUG Destroyed connection context.ldap2_140472239590864 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_ipaconfigstring_dnsversion_to_ipadnsversion 2022-12-17T23:55:45Z DEBUG raw: update_ipaconfigstring_dnsversion_to_ipadnsversion 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_dnszones 2022-12-17T23:55:45Z DEBUG raw: update_dnszones 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_dns_limits 2022-12-17T23:55:45Z DEBUG raw: update_dns_limits 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_sigden_extdom_broken_config 2022-12-17T23:55:45Z DEBUG raw: update_sigden_extdom_broken_config 2022-12-17T23:55:45Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:45Z DEBUG configured basedn for cn=IPA SIDGEN,cn=plugins,cn=config is okay 2022-12-17T23:55:45Z DEBUG configured basedn for cn=ipa_extdom_extop,cn=plugins,cn=config is okay 2022-12-17T23:55:45Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:45Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_sids 2022-12-17T23:55:45Z DEBUG raw: update_sids 2022-12-17T23:55:45Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:45Z DEBUG SIDs do not need to be generated 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_default_range 2022-12-17T23:55:45Z DEBUG raw: update_default_range 2022-12-17T23:55:45Z DEBUG default_range: ipaDomainIDRange entry found, skip plugin 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_default_trust_view 2022-12-17T23:55:45Z DEBUG raw: update_default_trust_view 2022-12-17T23:55:45Z DEBUG raw: adtrust_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG adtrust_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG AD Trusts are not enabled on this server 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_tdo_gidnumber 2022-12-17T23:55:45Z DEBUG raw: update_tdo_gidnumber 2022-12-17T23:55:45Z DEBUG raw: adtrust_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG adtrust_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG AD Trusts are not enabled on this server 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_tdo_to_new_layout 2022-12-17T23:55:45Z DEBUG raw: update_tdo_to_new_layout 2022-12-17T23:55:45Z DEBUG raw: adtrust_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG adtrust_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG AD Trusts are not enabled on this server 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_host_cifs_keytabs 2022-12-17T23:55:45Z DEBUG raw: update_host_cifs_keytabs 2022-12-17T23:55:45Z DEBUG raw: adtrust_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG adtrust_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG AD Trusts are not enabled on this server 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_tdo_default_read_keys_permissions 2022-12-17T23:55:45Z DEBUG raw: update_tdo_default_read_keys_permissions 2022-12-17T23:55:45Z DEBUG raw: adtrust_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG adtrust_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG AD Trusts are not enabled on this server 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_adtrust_agents_members 2022-12-17T23:55:45Z DEBUG raw: update_adtrust_agents_members 2022-12-17T23:55:45Z DEBUG raw: adtrust_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG adtrust_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG AD Trusts are not enabled on this server 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_ca_renewal_master 2022-12-17T23:55:45Z DEBUG raw: update_ca_renewal_master 2022-12-17T23:55:45Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:45Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:55:45Z DEBUG found CA renewal master master.redacted_domain.com 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_idrange_type 2022-12-17T23:55:45Z DEBUG raw: update_idrange_type 2022-12-17T23:55:45Z DEBUG update_idrange_type: search for ID ranges with no type set 2022-12-17T23:55:45Z DEBUG update_idrange_type: no ID range without type set found 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_pacs 2022-12-17T23:55:45Z DEBUG raw: update_pacs 2022-12-17T23:55:45Z DEBUG Adding nfs:NONE to default PAC types 2022-12-17T23:55:45Z DEBUG update_entry modlist [(0, 'ipakrbauthzdata', [b'nfs:NONE'])] 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_service_principalalias 2022-12-17T23:55:45Z DEBUG raw: update_service_principalalias 2022-12-17T23:55:45Z DEBUG update_service_principalalias: search for affected services 2022-12-17T23:55:45Z DEBUG update_service_principalalias: found 2 services to update, truncated: False 2022-12-17T23:55:45Z DEBUG update_entry modlist [(2, 'ipakrbprincipalalias', [b'ldap/master.redacted_domain.com@REDACTED_DOMAIN.COM']), (0, 'objectclass', [b'ipakrbprincipal'])] 2022-12-17T23:55:45Z DEBUG update_entry modlist [(2, 'ipakrbprincipalalias', [b'dogtag/master.redacted_domain.com@REDACTED_DOMAIN.COM']), (0, 'objectclass', [b'ipakrbprincipal'])] 2022-12-17T23:55:45Z DEBUG update_service_principalalias: all affected services updated 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:55:45Z DEBUG raw: update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:55:45Z DEBUG raw: ca_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG ca_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG No duplicates for IPA CA in LDAP 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_upload_cacrt 2022-12-17T23:55:45Z DEBUG raw: update_upload_cacrt 2022-12-17T23:55:45Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:55:45Z DEBUG raw: ca_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG ca_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG Starting external process 2022-12-17T23:55:45Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/', '-L', '-f', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/pwdfile.txt'] 2022-12-17T23:55:45Z DEBUG Process finished, return code=0 2022-12-17T23:55:45Z DEBUG stdout= Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI REDACTED_DOMAIN.COM IPA CA CT,C,C Server-Cert u,u,u 2022-12-17T23:55:45Z DEBUG stderr= 2022-12-17T23:55:45Z DEBUG Starting external process 2022-12-17T23:55:45Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/', '-L', '-n', 'REDACTED_DOMAIN.COM IPA CA', '-a', '-f', '/etc/dirsrv/slapd-REDACTED_DOMAIN-COM/pwdfile.txt'] 2022-12-17T23:55:45Z DEBUG Process finished, return code=0 2022-12-17T23:55:45Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIElzCCAv+gAwIBAgIBATANBgkqhkiG9w0BAQsFADA6MRgwFgYDVQQKDA9NT05J VkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0y MjEyMTcyMzUyMjdaFw00MjEyMTcyMzUyMjdaMDoxGDAWBgNVBAoMD01PTklWQUdS T1VQLkNPTTEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MIIBojANBgkq hkiG9w0BAQEFAAOCAY8AMIIBigKCAYEApvkK92tmgf6gzc7YvEOKeMIM2vA4ib/a ZYGjNA/rs6KKAKc9ZA3WWi/jmiskXCA6iidKX0EEBtlwYiC/mmRV5CG61/JG7s68 OK0SIxHQi0Li2yKrbeGjFlcveJuM0baTGS3bA995lbiqGNfKNl1LoLGTJs7QPA/N AhX6xqTD91W35ueYO8n5G2rAlgyQAGGvBntFeZeH6tA4DrZkHzBgSe/YZkllAN4h J0QOiBHvibSYjvvHE/XhILTZ5ZkPdxZQ8f9LwYH7v8mELmG2BjX9ipE3QgBuZ1F+ ntmHGyX68ReF2j8Mq98Ja1r88Uxg7Bely1GCFtN1883pwM8cYH786LeN5ELaR1UP zrHCqWJs5P1aGFcUtaVHhJV1TrA9ifXdj9LOyUVrBRzjjqysLYUB9O1f81qXGZwO F2My603PCN6wpQTxDULNjiSH7oDGTIZ30n5zf0X7WoBprvcTH3hP23CzJUuIKvgD tLyiwJIVBlbBeEUa/HtBm55HxmYDBGihAgMBAAGjgacwgaQwHwYDVR0jBBgwFoAU nCHM6adwr08G/ZX+WF9+wfZnocYwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8E BAMCAcYwHQYDVR0OBBYEFJwhzOmncK9PBv2V/lhffsH2Z6HGMEEGCCsGAQUFBwEB BDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL2lwYS1jYS5tb25pdmFncm91cC5jb20v Y2Evb2NzcDANBgkqhkiG9w0BAQsFAAOCAYEAmk/NzYQfLywaP+vwIQxW7csqgWym AanHwHEwQa4nGs3be80jYPyr9u8x2yStxX93o5U3IwHyzMprSN5VehUT4RuFwzMa AscI3cjTtn0IL0GTEjeTMtUYvhj6bNg58tS1RRYDqUcI4Ug5r/KjPxfcTVDh7/XS X1MDgWwbf092Sx7+3OnBwxvkgk4xYthwRVfsPOT4UG5Wiad2q149ZYDWhzf+Kwft 5hBoY1ZSvxoNzXjXP5ch25ObVpmw03OYFLWtMDfcsKJim+VvS0EN9TvYPqcLYzkf EfPn4kGwg/1+oz6zT6ODkfAdePqF3FqVD93ZqlX6o6R0jILJ+lLVDhKD9hZ/tJE/ 1JnBjdIuXzGQgzCayXCpSIkoDYVDtxFHp5p0s5Xm3kcci9bmB9P8XtlVQ25ha2fM l4/cWzI5U9kn7NSrksxBqlwLYf3ffCZ6bkBwBzto6xst4grBqvDy1xusxEafx6+V ZAxH5ep/2YvBzDDclc5WvZ447jL6iPS+P9lT -----END CERTIFICATE----- 2022-12-17T23:55:45Z DEBUG stderr= 2022-12-17T23:55:45Z DEBUG update_entry modlist [(2, 'cACertificate;binary', [b'0\x82\x04\x970\x82\x02\xff\xa0\x03\x02\x01\x02\x02\x01\x010\r\x06\t*\x86H\x86\xf7\r\x01\x01\x0b\x05\x000:1\x180\x16\x06\x03U\x04\n\x0c\x0fREDACTED_DOMAIN.COM1\x1e0\x1c\x06\x03U\x04\x03\x0c\x15Certificate Authority0\x1e\x17\r221217235227Z\x17\r421217235227Z0:1\x180\x16\x06\x03U\x04\n\x0c\x0fREDACTED_DOMAIN.COM1\x1e0\x1c\x06\x03U\x04\x03\x0c\x15Certificate Authority0\x82\x01\xa20\r\x06\t*\x86H\x86\xf7\r\x01\x01\x01\x05\x00\x03\x82\x01\x8f\x000\x82\x01\x8a\x02\x82\x01\x81\x00\xa6\xf9\n\xf7kf\x81\xfe\xa0\xcd\xce\xd8\xbcC\x8ax\xc2\x0c\xda\xf08\x89\xbf\xdae\x81\xa34\x0f\xeb\xb3\xa2\x8a\x00\xa7=d\r\xd6Z/\xe3\x9a+$\\ :\x8a\'J_A\x04\x06\xd9pb \xbf\x9adU\xe4!\xba\xd7\xf2F\xee\xce\xbc8\xad\x12#\x11\xd0\x8bB\xe2\xdb"\xabm\xe1\xa3\x16W/x\x9b\x8c\xd1\xb6\x93\x19-\xdb\x03\xdfy\x95\xb8\xaa\x18\xd7\xca6]K\xa0\xb1\x93&\xce\xd0<\x0f\xcd\x02\x15\xfa\xc6\xa4\xc3\xf7U\xb7\xe6\xe7\x98;\xc9\xf9\x1bj\xc0\x96\x0c\x90\x00a\xaf\x06{Ey\x97\x87\xea\xd08\x0e\xb6d\x1f0`I\xef\xd8fIe\x00\xde!\'D\x0e\x88\x11\xef\x89\xb4\x98\x8e\xfb\xc7\x13\xf5\xe1 \xb4\xd9\xe5\x99\x0fw\x16P\xf1\xffK\xc1\x81\xfb\xbf\xc9\x84.a\xb6\x065\xfd\x8a\x917B\x00ngQ~\x9e\xd9\x87\x1b%\xfa\xf1\x17\x85\xda?\x0c\xab\xdf\tkZ\xfc\xf1L`\xec\x17\xa5\xcbQ\x82\x16\xd3u\xf3\xcd\xe9\xc0\xcf\x1c`~\xfc\xe8\xb7\x8d\xe4B\xdaGU\x0f\xce\xb1\xc2\xa9bl\xe4\xfdZ\x18W\x14\xb5\xa5G\x84\x95uN\xb0=\x89\xf5\xdd\x8f\xd2\xce\xc9Ek\x05\x1c\xe3\x8e\xac\xac-\x85\x01\xf4\xed_\xf3Z\x97\x19\x9c\x0e\x17c2\xebM\xcf\x08\xde\xb0\xa5\x04\xf1\rB\xcd\x8e$\x87\xee\x80\xc6L\x86w\xd2~s\x7fE\xfbZ\x80i\xae\xf7\x13\x1fxO\xdbp\xb3%K\x88*\xf8\x03\xb4\xbc\xa2\xc0\x92\x15\x06V\xc1xE\x1a\xfc{A\x9b\x9eG\xc6f\x03\x04h\xa1\x02\x03\x01\x00\x01\xa3\x81\xa70\x81\xa40\x1f\x06\x03U\x1d#\x04\x180\x16\x80\x14\x9c!\xcc\xe9\xa7p\xafO\x06\xfd\x95\xfeX_~\xc1\xf6g\xa1\xc60\x0f\x06\x03U\x1d\x13\x01\x01\xff\x04\x050\x03\x01\x01\xff0\x0e\x06\x03U\x1d\x0f\x01\x01\xff\x04\x04\x03\x02\x01\xc60\x1d\x06\x03U\x1d\x0e\x04\x16\x04\x14\x9c!\xcc\xe9\xa7p\xafO\x06\xfd\x95\xfeX_~\xc1\xf6g\xa1\xc60A\x06\x08+\x06\x01\x05\x05\x07\x01\x01\x0450301\x06\x08+\x06\x01\x05\x05\x070\x01\x86%http://ipa-ca.redacted_domain.com/ca/ocsp0\r\x06\t*\x86H\x86\xf7\r\x01\x01\x0b\x05\x00\x03\x82\x01\x81\x00\x9aO\xcd\xcd\x84\x1f/,\x1a?\xeb\xf0!\x0cV\xed\xcb*\x81l\xa6\x01\xa9\xc7\xc0q0A\xae\'\x1a\xcd\xdb{\xcd#`\xfc\xab\xf6\xef1\xdb$\xad\xc5\x7fw\xa3\x957#\x01\xf2\xcc\xcakH\xdeUz\x15\x13\xe1\x1b\x85\xc33\x1a\x02\xc7\x08\xdd\xc8\xd3\xb6}\x08/A\x93\x127\x932\xd5\x18\xbe\x18\xfal\xd89\xf2\xd4\xb5E\x16\x03\xa9G\x08\xe1H9\xaf\xf2\xa3?\x17\xdcMP\xe1\xef\xf5\xd2_S\x03\x81l\x1b\x7fOvK\x1e\xfe\xdc\xe9\xc1\xc3\x1b\xe4\x82N1b\xd8pEW\xec<\xe4\xf8PnV\x89\xa7v\xab^=e\x80\xd6\x877\xfe+\x07\xed\xe6\x10hcVR\xbf\x1a\r\xcdx\xd7?\x97!\xdb\x93\x9bV\x99\xb0\xd3s\x98\x14\xb5\xad07\xdc\xb0\xa2b\x9b\xe5oKA\r\xf5;\xd8>\xa7\x0bc9\x1f\x11\xf3\xe7\xe2A\xb0\x83\xfd~\xa3>\xb3O\xa3\x83\x91\xf0\x1dx\xfa\x85\xdcZ\x95\x0f\xdd\xd9\xaaU\xfa\xa3\xa4t\x8c\x82\xc9\xfaR\xd5\x0e\x12\x83\xf6\x16\x7f\xb4\x91?\xd4\x99\xc1\x8d\xd2._1\x90\x830\x9a\xc9p\xa9H\x89(\r\x85C\xb7\x11G\xa7\x9at\xb3\x95\xe6\xdeG\x1c\x8b\xd6\xe6\x07\xd3\xfc^\xd9UCnakg\xcc\x97\x8f\xdc[29S\xd9\'\xec\xd4\xab\x92\xccA\xaa\\\x0ba\xfd\xdf|&zn@p\x07;h\xeb\x1b-\xe2\n\xc1\xaa\xf0\xf2\xd7\x1b\xac\xc4F\x9f\xc7\xaf\x95d\x0cG\xe5\xea\x7f\xd9\x8b\xc1\xcc0\xdc\x95\xceV\xbd\x9e8\xee2\xfa\x88\xf4\xbe?\xd9S']), (2, 'ipaKeyTrust', [b'trusted']), (2, 'ipaKeyExtUsage', [b'1.3.6.1.5.5.7.3.3', b'1.3.6.1.5.5.7.3.2', b'1.3.6.1.5.5.7.3.1', b'1.3.6.1.5.5.7.3.4']), (2, 'ipaConfigString', [b'ipaCa', b'compatCA']), (2, 'ipaPublicKey', [b'0\x82\x01\xa20\r\x06\t*\x86H\x86\xf7\r\x01\x01\x01\x05\x00\x03\x82\x01\x8f\x000\x82\x01\x8a\x02\x82\x01\x81\x00\xa6\xf9\n\xf7kf\x81\xfe\xa0\xcd\xce\xd8\xbcC\x8ax\xc2\x0c\xda\xf08\x89\xbf\xdae\x81\xa34\x0f\xeb\xb3\xa2\x8a\x00\xa7=d\r\xd6Z/\xe3\x9a+$\\ :\x8a\'J_A\x04\x06\xd9pb \xbf\x9adU\xe4!\xba\xd7\xf2F\xee\xce\xbc8\xad\x12#\x11\xd0\x8bB\xe2\xdb"\xabm\xe1\xa3\x16W/x\x9b\x8c\xd1\xb6\x93\x19-\xdb\x03\xdfy\x95\xb8\xaa\x18\xd7\xca6]K\xa0\xb1\x93&\xce\xd0<\x0f\xcd\x02\x15\xfa\xc6\xa4\xc3\xf7U\xb7\xe6\xe7\x98;\xc9\xf9\x1bj\xc0\x96\x0c\x90\x00a\xaf\x06{Ey\x97\x87\xea\xd08\x0e\xb6d\x1f0`I\xef\xd8fIe\x00\xde!\'D\x0e\x88\x11\xef\x89\xb4\x98\x8e\xfb\xc7\x13\xf5\xe1 \xb4\xd9\xe5\x99\x0fw\x16P\xf1\xffK\xc1\x81\xfb\xbf\xc9\x84.a\xb6\x065\xfd\x8a\x917B\x00ngQ~\x9e\xd9\x87\x1b%\xfa\xf1\x17\x85\xda?\x0c\xab\xdf\tkZ\xfc\xf1L`\xec\x17\xa5\xcbQ\x82\x16\xd3u\xf3\xcd\xe9\xc0\xcf\x1c`~\xfc\xe8\xb7\x8d\xe4B\xdaGU\x0f\xce\xb1\xc2\xa9bl\xe4\xfdZ\x18W\x14\xb5\xa5G\x84\x95uN\xb0=\x89\xf5\xdd\x8f\xd2\xce\xc9Ek\x05\x1c\xe3\x8e\xac\xac-\x85\x01\xf4\xed_\xf3Z\x97\x19\x9c\x0e\x17c2\xebM\xcf\x08\xde\xb0\xa5\x04\xf1\rB\xcd\x8e$\x87\xee\x80\xc6L\x86w\xd2~s\x7fE\xfbZ\x80i\xae\xf7\x13\x1fxO\xdbp\xb3%K\x88*\xf8\x03\xb4\xbc\xa2\xc0\x92\x15\x06V\xc1xE\x1a\xfc{A\x9b\x9eG\xc6f\x03\x04h\xa1\x02\x03\x01\x00\x01']), (2, 'ipaCertIssuerSerial', [b'CN=Certificate Authority,O=REDACTED_DOMAIN.COM;1']), (2, 'ipaCertSubject', [b'CN=Certificate Authority,O=REDACTED_DOMAIN.COM']), (2, 'objectClass', [b'ipaCertificate', b'pkiCA', b'ipaKeyPolicy']), (2, 'cn', [b'REDACTED_DOMAIN.COM IPA CA'])] 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_ra_cert_store 2022-12-17T23:55:45Z DEBUG raw: update_ra_cert_store 2022-12-17T23:55:45Z DEBUG raw: ca_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG ca_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: update_mapping_Guests_to_nobody 2022-12-17T23:55:45Z DEBUG raw: update_mapping_Guests_to_nobody 2022-12-17T23:55:45Z DEBUG raw: adtrust_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG adtrust_is_enabled(version='2.251') 2022-12-17T23:55:45Z DEBUG AD Trusts are not enabled on this server 2022-12-17T23:55:45Z DEBUG Executing upgrade plugin: fix_kra_people_entry 2022-12-17T23:55:45Z DEBUG raw: fix_kra_people_entry 2022-12-17T23:55:45Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:45Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:55:45Z DEBUG Starting external process 2022-12-17T23:55:45Z DEBUG args=['pki-server', 'subsystem-show', 'kra'] 2022-12-17T23:55:46Z DEBUG Process finished, return code=1 2022-12-17T23:55:46Z DEBUG stdout= 2022-12-17T23:55:46Z DEBUG stderr=ERROR: ERROR: No kra subsystem in instance pki-tomcat. 2022-12-17T23:55:46Z DEBUG Executing upgrade plugin: update_pwpolicy 2022-12-17T23:55:46Z DEBUG raw: update_pwpolicy 2022-12-17T23:55:46Z DEBUG update_pwpolicy: found 1 policies to update, truncated: False 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'objectclass', [b'ipapwdpolicy'])] 2022-12-17T23:55:46Z DEBUG update_pwpolicy: all policies updated 2022-12-17T23:55:46Z DEBUG Executing upgrade plugin: update_pwpolicy_grace 2022-12-17T23:55:46Z DEBUG raw: update_pwpolicy_grace 2022-12-17T23:55:46Z DEBUG update_pwpolicy: found 1 policies to update, truncated: False 2022-12-17T23:55:46Z DEBUG update_entry modlist [(2, 'passwordgracelimit', [b'-1'])] 2022-12-17T23:55:46Z DEBUG update_pwpolicy: all policies updated 2022-12-17T23:55:46Z DEBUG Executing upgrade plugin: update_master_to_dnsforwardzones 2022-12-17T23:55:46Z DEBUG raw: update_master_to_dnsforwardzones 2022-12-17T23:55:46Z DEBUG raw: dnsconfig_show(all=True, version='2.251') 2022-12-17T23:55:46Z DEBUG dnsconfig_show(rights=False, all=True, raw=False, version='2.251') 2022-12-17T23:55:46Z DEBUG Executing upgrade plugin: update_dnsforward_emptyzones 2022-12-17T23:55:46Z DEBUG raw: update_dnsforward_emptyzones 2022-12-17T23:55:46Z DEBUG raw: dnsconfig_show(all=True, version='2.251') 2022-12-17T23:55:46Z DEBUG dnsconfig_show(rights=False, all=True, raw=False, version='2.251') 2022-12-17T23:55:46Z DEBUG Executing upgrade plugin: update_managed_post 2022-12-17T23:55:46Z DEBUG raw: update_managed_post 2022-12-17T23:55:46Z DEBUG Executing upgrade plugin: update_managed_permissions 2022-12-17T23:55:46Z DEBUG raw: update_managed_permissions 2022-12-17T23:55:46Z DEBUG Anonymous ACI not found 2022-12-17T23:55:46Z DEBUG Updating managed permissions for automember 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Read Automember Definitions 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Read Automember Definitions 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "automemberdefaultgroup || automemberdisabled || automemberfilter || automembergroupingattr || automemberscope || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberdefinition)")(version 3.0;acl "permission:System: Read Automember Definitions";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "automemberdefaultgroup || automemberdisabled || automemberfilter || automembergroupingattr || automemberscope || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberdefinition)")(version 3.0;acl "permission:System: Read Automember Definitions";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Read Automember Rules 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Read Automember Rules 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "automemberexclusiveregex || automemberinclusiveregex || automembertargetgroup || cn || createtimestamp || description || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberregexrule)")(version 3.0;acl "permission:System: Read Automember Rules";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=automember,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "automemberexclusiveregex || automemberinclusiveregex || automembertargetgroup || cn || createtimestamp || description || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberregexrule)")(version 3.0;acl "permission:System: Read Automember Rules";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Read Automember Tasks 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Read Automember Tasks 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///cn=*,cn=automember rebuild membership,cn=tasks,cn=config")(version 3.0;acl "permission:System: Read Automember Tasks";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=tasks,cn=config 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "*")(target = "ldap:///cn=*,cn=automember rebuild membership,cn=tasks,cn=config")(version 3.0;acl "permission:System: Read Automember Tasks";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permissions for automountkey 2022-12-17T23:55:46Z DEBUG Legacy permission Add Automount keys not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Add Automount Keys 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Add Automount Keys 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=automount)")(version 3.0;acl "permission:System: Add Automount Keys";allow (add) groupdn = "ldap:///cn=System: Add Automount Keys,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=automount,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=automount)")(version 3.0;acl "permission:System: Add Automount Keys";allow (add) groupdn = "ldap:///cn=System: Add Automount Keys,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Legacy permission Modify Automount keys not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Modify Automount Keys 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Modify Automount Keys 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "automountinformation || automountkey || description")(targetfilter = "(objectclass=automount)")(version 3.0;acl "permission:System: Modify Automount Keys";allow (write) groupdn = "ldap:///cn=System: Modify Automount Keys,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=automount,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "automountinformation || automountkey || description")(targetfilter = "(objectclass=automount)")(version 3.0;acl "permission:System: Modify Automount Keys";allow (write) groupdn = "ldap:///cn=System: Modify Automount Keys,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Legacy permission Remove Automount keys not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Remove Automount Keys 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Remove Automount Keys 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=automount)")(version 3.0;acl "permission:System: Remove Automount Keys";allow (delete) groupdn = "ldap:///cn=System: Remove Automount Keys,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=automount,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=automount)")(version 3.0;acl "permission:System: Remove Automount Keys";allow (delete) groupdn = "ldap:///cn=System: Remove Automount Keys,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permissions for automountlocation 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Add Automount Locations 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Add Automount Locations 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Add Automount Locations";allow (add) groupdn = "ldap:///cn=System: Add Automount Locations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=automount,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Add Automount Locations";allow (add) groupdn = "ldap:///cn=System: Add Automount Locations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Read Automount Configuration 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Read Automount Configuration 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "automountinformation || automountkey || automountmapname || cn || createtimestamp || description || entryusn || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Automount Configuration";allow (compare,read,search) userdn = "ldap:///anyone";)' to cn=automount,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "automountinformation || automountkey || automountmapname || cn || createtimestamp || description || entryusn || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Automount Configuration";allow (compare,read,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Remove Automount Locations 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Remove Automount Locations 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Remove Automount Locations";allow (delete) groupdn = "ldap:///cn=System: Remove Automount Locations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=automount,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Remove Automount Locations";allow (delete) groupdn = "ldap:///cn=System: Remove Automount Locations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permissions for automountmap 2022-12-17T23:55:46Z DEBUG Legacy permission Add Automount maps not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Add Automount Maps 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Add Automount Maps 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=automountmap)")(version 3.0;acl "permission:System: Add Automount Maps";allow (add) groupdn = "ldap:///cn=System: Add Automount Maps,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=automount,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=automountmap)")(version 3.0;acl "permission:System: Add Automount Maps";allow (add) groupdn = "ldap:///cn=System: Add Automount Maps,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Legacy permission Modify Automount maps not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Modify Automount Maps 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Modify Automount Maps 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "automountmapname || description")(targetfilter = "(objectclass=automountmap)")(version 3.0;acl "permission:System: Modify Automount Maps";allow (write) groupdn = "ldap:///cn=System: Modify Automount Maps,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=automount,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "automountmapname || description")(targetfilter = "(objectclass=automountmap)")(version 3.0;acl "permission:System: Modify Automount Maps";allow (write) groupdn = "ldap:///cn=System: Modify Automount Maps,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Legacy permission Remove Automount maps not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Remove Automount Maps 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Remove Automount Maps 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=automountmap)")(version 3.0;acl "permission:System: Remove Automount Maps";allow (delete) groupdn = "ldap:///cn=System: Remove Automount Maps,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=automount,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=automountmap)")(version 3.0;acl "permission:System: Remove Automount Maps";allow (delete) groupdn = "ldap:///cn=System: Remove Automount Maps,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permissions for ca 2022-12-17T23:55:46Z DEBUG Legacy permission Add CA not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Add CA 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Add CA 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Add CA";allow (add) groupdn = "ldap:///cn=System: Add CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=cas,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Add CA";allow (add) groupdn = "ldap:///cn=System: Add CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Legacy permission Delete CA not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Delete CA 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Delete CA 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Delete CA";allow (delete) groupdn = "ldap:///cn=System: Delete CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=cas,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Delete CA";allow (delete) groupdn = "ldap:///cn=System: Delete CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Legacy permission Modify CA not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Modify CA 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Modify CA 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "cn || description")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Modify CA";allow (write) groupdn = "ldap:///cn=System: Modify CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=cas,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || description")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Modify CA";allow (write) groupdn = "ldap:///cn=System: Modify CA,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Read CAs 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Read CAs 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || ipacaid || ipacaissuerdn || ipacarandomserialnumberversion || ipacasubjectdn || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Read CAs";allow (compare,read,search) userdn = "ldap:///all";)' to cn=cas,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || ipacaid || ipacaissuerdn || ipacarandomserialnumberversion || ipacasubjectdn || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Read CAs";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permissions for caacl 2022-12-17T23:55:46Z DEBUG Legacy permission Add CA ACL not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Add CA ACL 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Add CA ACL 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Add CA ACL";allow (add) groupdn = "ldap:///cn=System: Add CA ACL,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=caacls,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Add CA ACL";allow (add) groupdn = "ldap:///cn=System: Add CA ACL,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Legacy permission Delete CA ACL not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Delete CA ACL 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Delete CA ACL 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Delete CA ACL";allow (delete) groupdn = "ldap:///cn=System: Delete CA ACL,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=caacls,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Delete CA ACL";allow (delete) groupdn = "ldap:///cn=System: Delete CA ACL,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Legacy permission Manage CA ACL membership not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Manage CA ACL Membership 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Manage CA ACL Membership 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "hostcategory || ipacacategory || ipacertprofilecategory || ipamemberca || ipamembercertprofile || memberhost || memberservice || memberuser || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Manage CA ACL Membership";allow (write) groupdn = "ldap:///cn=System: Manage CA ACL Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=caacls,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "hostcategory || ipacacategory || ipacertprofilecategory || ipamemberca || ipamembercertprofile || memberhost || memberservice || memberuser || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Manage CA ACL Membership";allow (write) groupdn = "ldap:///cn=System: Manage CA ACL Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Legacy permission Modify CA ACL not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Modify CA ACL 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Modify CA ACL 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "cn || description || ipaenabledflag")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Modify CA ACL";allow (write) groupdn = "ldap:///cn=System: Modify CA ACL,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=caacls,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || description || ipaenabledflag")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Modify CA ACL";allow (write) groupdn = "ldap:///cn=System: Modify CA ACL,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Read CA ACLs 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Read CA ACLs 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipacacategory || ipacertprofilecategory || ipaenabledflag || ipamemberca || ipamembercertprofile || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Read CA ACLs";allow (compare,read,search) userdn = "ldap:///all";)' to cn=caacls,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipacacategory || ipacertprofilecategory || ipaenabledflag || ipamemberca || ipamembercertprofile || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Read CA ACLs";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permissions for certmapconfig 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Modify Certmap Configuration 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Modify Certmap Configuration 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Modify Certmap Configuration";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=certmap,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Modify Certmap Configuration";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Read Certmap Configuration 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Read Certmap Configuration 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "cn || ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Read Certmap Configuration";allow (compare,read,search) userdn = "ldap:///all";)' to cn=certmap,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Read Certmap Configuration";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permissions for certmaprule 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Add Certmap Rules 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Add Certmap Rules 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Add Certmap Rules";allow (add) groupdn = "ldap:///cn=System: Add Certmap Rules,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=certmaprules,cn=certmap,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Add Certmap Rules";allow (add) groupdn = "ldap:///cn=System: Add Certmap Rules,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Delete Certmap Rules 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Delete Certmap Rules 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Delete Certmap Rules";allow (delete) groupdn = "ldap:///cn=System: Delete Certmap Rules,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=certmaprules,cn=certmap,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Delete Certmap Rules";allow (delete) groupdn = "ldap:///cn=System: Delete Certmap Rules,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Modify Certmap Rules 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Modify Certmap Rules 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "associateddomain || cn || description || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Modify Certmap Rules";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Rules,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=certmaprules,cn=certmap,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "associateddomain || cn || description || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Modify Certmap Rules";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Rules,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Read Certmap Rules 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Read Certmap Rules 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "associateddomain || cn || createtimestamp || description || entryusn || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Read Certmap Rules";allow (compare,read,search) userdn = "ldap:///all";)' to cn=certmaprules,cn=certmap,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "associateddomain || cn || createtimestamp || description || entryusn || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Read Certmap Rules";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permissions for certprofile 2022-12-17T23:55:46Z DEBUG Legacy permission Delete Certificate Profile not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Delete Certificate Profile 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Delete Certificate Profile 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Delete Certificate Profile";allow (delete) groupdn = "ldap:///cn=System: Delete Certificate Profile,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=certprofiles,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Delete Certificate Profile";allow (delete) groupdn = "ldap:///cn=System: Delete Certificate Profile,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Legacy permission Import Certificate Profile not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Import Certificate Profile 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Import Certificate Profile 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Import Certificate Profile";allow (add) groupdn = "ldap:///cn=System: Import Certificate Profile,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=certprofiles,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Import Certificate Profile";allow (add) groupdn = "ldap:///cn=System: Import Certificate Profile,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Legacy permission Modify Certificate Profile not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Modify Certificate Profile 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Modify Certificate Profile 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "cn || description || ipacertprofilestoreissued")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Modify Certificate Profile";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Profile,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=certprofiles,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || description || ipacertprofilestoreissued")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Modify Certificate Profile";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Profile,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Read Certificate Profiles 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Read Certificate Profiles 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || ipacertprofilestoreissued || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Read Certificate Profiles";allow (compare,read,search) userdn = "ldap:///all";)' to cn=certprofiles,cn=ca,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || ipacertprofilestoreissued || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Read Certificate Profiles";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permissions for config 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Read Global Configuration 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Read Global Configuration 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipacertificatesubjectbase || ipaconfigstring || ipacustomfields || ipadefaultemaildomain || ipadefaultloginshell || ipadefaultprimarygroup || ipadomainresolutionorder || ipagroupobjectclasses || ipagroupsearchfields || ipahomesrootdir || ipakrbauthzdata || ipamaxhostnamelength || ipamaxusernamelength || ipamigrationenabled || ipapwdexpadvnotify || ipasearchrecordslimit || ipasearchtimelimit || ipaselinuxusermapdefault || ipaselinuxusermaporder || ipauserauthtype || ipauserdefaultsubordinateid || ipauserobjectclasses || ipausersearchfields || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaguiconfig)")(version 3.0;acl "permission:System: Read Global Configuration";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ipaConfig,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || ipacertificatesubjectbase || ipaconfigstring || ipacustomfields || ipadefaultemaildomain || ipadefaultloginshell || ipadefaultprimarygroup || ipadomainresolutionorder || ipagroupobjectclasses || ipagroupsearchfields || ipahomesrootdir || ipakrbauthzdata || ipamaxhostnamelength || ipamaxusernamelength || ipamigrationenabled || ipapwdexpadvnotify || ipasearchrecordslimit || ipasearchtimelimit || ipaselinuxusermapdefault || ipaselinuxusermaporder || ipauserauthtype || ipauserdefaultsubordinateid || ipauserobjectclasses || ipausersearchfields || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaguiconfig)")(version 3.0;acl "permission:System: Read Global Configuration";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permissions for cosentry 2022-12-17T23:55:46Z DEBUG Legacy permission Add Group Password Policy costemplate not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Add Group Password Policy costemplate 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Add Group Password Policy costemplate 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Add Group Password Policy costemplate";allow (add) groupdn = "ldap:///cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=cosTemplates,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Add Group Password Policy costemplate";allow (add) groupdn = "ldap:///cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Legacy permission Delete Group Password Policy costemplate not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Delete Group Password Policy costemplate 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Delete Group Password Policy costemplate 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Delete Group Password Policy costemplate";allow (delete) groupdn = "ldap:///cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=cosTemplates,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Delete Group Password Policy costemplate";allow (delete) groupdn = "ldap:///cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Legacy permission Modify Group Password Policy costemplate not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Modify Group Password Policy costemplate 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Modify Group Password Policy costemplate 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "cospriority")(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Modify Group Password Policy costemplate";allow (write) groupdn = "ldap:///cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=cosTemplates,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cospriority")(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Modify Group Password Policy costemplate";allow (write) groupdn = "ldap:///cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Read Group Password Policy costemplate 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Read Group Password Policy costemplate 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "cn || cospriority || createtimestamp || entryusn || krbpwdpolicyreference || modifytimestamp || objectclass")(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Read Group Password Policy costemplate";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=cosTemplates,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || cospriority || createtimestamp || entryusn || krbpwdpolicyreference || modifytimestamp || objectclass")(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Read Group Password Policy costemplate";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Updating managed permissions for dnsconfig 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Read DNS Configuration 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Read DNS Configuration 2022-12-17T23:55:46Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:46Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:46Z DEBUG Legacy permission Write DNS Configuration not found 2022-12-17T23:55:46Z DEBUG Updating managed permission: System: Write DNS Configuration 2022-12-17T23:55:46Z DEBUG Updating ACI for managed permission: System: Write DNS Configuration 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permissions for dnsserver 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Modify DNS Servers Configuration 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Modify DNS Servers Configuration 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Read DNS Servers Configuration 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Read DNS Servers Configuration 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permissions for dnszone 2022-12-17T23:55:47Z DEBUG Legacy permission add dns entries not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Add DNS Entries 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Add DNS Entries 2022-12-17T23:55:47Z DEBUG Adding ACI '(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Manage DNSSEC keys 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Manage DNSSEC keys 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Manage DNSSEC metadata 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Manage DNSSEC metadata 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Read DNS Entries 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Read DNS Entries 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Legacy permission 'Read DNS Entries' not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Read DNSSEC metadata 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Read DNSSEC metadata 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Legacy permission remove dns entries not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Remove DNS Entries 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Remove DNS Entries 2022-12-17T23:55:47Z DEBUG Adding ACI '(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Legacy permission update dns entries not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Update DNS Entries 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Update DNS Entries 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permissions for group 2022-12-17T23:55:47Z DEBUG Legacy permission Add Groups not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Add Groups 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Add Groups 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Add Groups";allow (add) groupdn = "ldap:///cn=System: Add Groups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Add Groups";allow (add) groupdn = "ldap:///cn=System: Add Groups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Modify External Group Membership 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Modify External Group Membership 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "ipaexternalmember")(targetfilter = "(objectclass=ipaexternalgroup)")(version 3.0;acl "permission:System: Modify External Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipaexternalmember")(targetfilter = "(objectclass=ipaexternalgroup)")(version 3.0;acl "permission:System: Modify External Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Legacy permission Modify Group membership not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Modify Group Membership 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Modify Group Membership 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "member")(targetfilter = "(&(!(cn=admins))(objectclass=ipausergroup))")(version 3.0;acl "permission:System: Modify Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "member")(targetfilter = "(&(!(cn=admins))(objectclass=ipausergroup))")(version 3.0;acl "permission:System: Modify Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Legacy permission Modify Groups not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Modify Groups 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Modify Groups 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "cn || description || gidnumber || ipauniqueid || membermanager || mepmanagedby || objectclass")(targetfilter = "(&(!(cn=admins))(|(objectclass=ipausergroup)(objectclass=posixgroup)))")(version 3.0;acl "permission:System: Modify Groups";allow (write) groupdn = "ldap:///cn=System: Modify Groups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || description || gidnumber || ipauniqueid || membermanager || mepmanagedby || objectclass")(targetfilter = "(&(!(cn=admins))(|(objectclass=ipausergroup)(objectclass=posixgroup)))")(version 3.0;acl "permission:System: Modify Groups";allow (write) groupdn = "ldap:///cn=System: Modify Groups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Read External Group Membership 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Read External Group Membership 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "ipaexternalmember")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read External Group Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipaexternalmember")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read External Group Membership";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Read Group Compat Tree 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Read Group Compat Tree 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Read Group Membership 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Read Group Membership 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "member || memberhost || memberof || memberuid || memberuser")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Group Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "member || memberhost || memberof || memberuid || memberuser")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Group Membership";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Read Group Views Compat Tree 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Read Group Views Compat Tree 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Read Groups 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Read Groups 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || gidnumber || ipaexternalmember || ipantsecurityidentifier || ipauniqueid || membermanager || mepmanagedby || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Groups";allow (compare,read,search) userdn = "ldap:///anyone";)' to cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || gidnumber || ipaexternalmember || ipantsecurityidentifier || ipauniqueid || membermanager || mepmanagedby || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Groups";allow (compare,read,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:47Z DEBUG Legacy permission Remove Groups not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Remove Groups 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Remove Groups 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetfilter = "(&(!(|(cn=admins)(cn=trust admins)(cn=default smb group)))(|(objectclass=ipausergroup)(objectclass=posixgroup)))")(version 3.0;acl "permission:System: Remove Groups";allow (delete) groupdn = "ldap:///cn=System: Remove Groups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(&(!(|(cn=admins)(cn=trust admins)(cn=default smb group)))(|(objectclass=ipausergroup)(objectclass=posixgroup)))")(version 3.0;acl "permission:System: Remove Groups";allow (delete) groupdn = "ldap:///cn=System: Remove Groups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permissions for hbacrule 2022-12-17T23:55:47Z DEBUG Legacy permission Add HBAC rule not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Add HBAC Rule 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Add HBAC Rule 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Add HBAC Rule";allow (add) groupdn = "ldap:///cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Add HBAC Rule";allow (add) groupdn = "ldap:///cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Legacy permission Delete HBAC rule not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Delete HBAC Rule 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Delete HBAC Rule 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Delete HBAC Rule";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Delete HBAC Rule";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Legacy permission Manage HBAC rule membership not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Manage HBAC Rule Membership 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Manage HBAC Rule Membership 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "externalhost || memberhost || memberservice || memberuser")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Manage HBAC Rule Membership";allow (write) groupdn = "ldap:///cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "externalhost || memberhost || memberservice || memberuser")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Manage HBAC Rule Membership";allow (write) groupdn = "ldap:///cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Legacy permission Modify HBAC rule not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Modify HBAC Rule 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Modify HBAC Rule 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "accessruletype || accesstime || cn || description || hostcategory || ipaenabledflag || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Modify HBAC Rule";allow (write) groupdn = "ldap:///cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "accessruletype || accesstime || cn || description || hostcategory || ipaenabledflag || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Modify HBAC Rule";allow (write) groupdn = "ldap:///cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Read HBAC Rules 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Read HBAC Rules 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "accessruletype || accesstime || cn || createtimestamp || description || entryusn || externalhost || hostcategory || ipaenabledflag || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Read HBAC Rules";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "accessruletype || accesstime || cn || createtimestamp || description || entryusn || externalhost || hostcategory || ipaenabledflag || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Read HBAC Rules";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permissions for hbacsvc 2022-12-17T23:55:47Z DEBUG Legacy permission Add HBAC services not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Add HBAC Services 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Add HBAC Services 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahbacservice)")(version 3.0;acl "permission:System: Add HBAC Services";allow (add) groupdn = "ldap:///cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipahbacservice)")(version 3.0;acl "permission:System: Add HBAC Services";allow (add) groupdn = "ldap:///cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Legacy permission Delete HBAC services not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Delete HBAC Services 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Delete HBAC Services 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahbacservice)")(version 3.0;acl "permission:System: Delete HBAC Services";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipahbacservice)")(version 3.0;acl "permission:System: Delete HBAC Services";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Read HBAC Services 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Read HBAC Services 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || ipauniqueid || memberof || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahbacservice)")(version 3.0;acl "permission:System: Read HBAC Services";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hbacservices,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || ipauniqueid || memberof || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahbacservice)")(version 3.0;acl "permission:System: Read HBAC Services";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permissions for hbacsvcgroup 2022-12-17T23:55:47Z DEBUG Legacy permission Add HBAC service groups not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Add HBAC Service Groups 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Add HBAC Service Groups 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Add HBAC Service Groups";allow (add) groupdn = "ldap:///cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=hbacservicegroups,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Add HBAC Service Groups";allow (add) groupdn = "ldap:///cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Legacy permission Delete HBAC service groups not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Delete HBAC Service Groups 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Delete HBAC Service Groups 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Delete HBAC Service Groups";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=hbacservicegroups,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Delete HBAC Service Groups";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Legacy permission Manage HBAC service group membership not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Manage HBAC Service Group Membership 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Manage HBAC Service Group Membership 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "member")(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Manage HBAC Service Group Membership";allow (write) groupdn = "ldap:///cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=hbacservicegroups,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "member")(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Manage HBAC Service Group Membership";allow (write) groupdn = "ldap:///cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Read HBAC Service Groups 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Read HBAC Service Groups 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || member || memberhost || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Read HBAC Service Groups";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hbacservicegroups,cn=hbac,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || member || memberhost || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Read HBAC Service Groups";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permissions for host 2022-12-17T23:55:47Z DEBUG Legacy permission Add Hosts not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Add Hosts 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Add Hosts 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Legacy permission Add krbPrincipalName to a host not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Add krbPrincipalName to a Host 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Add krbPrincipalName to a Host 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Legacy permission Enroll a host not found 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Enroll a Host 2022-12-17T23:55:47Z DEBUG Updating ACI for managed permission: System: Enroll a Host 2022-12-17T23:55:47Z DEBUG Adding ACI '(targetattr = "enrolledby || nshardwareplatform || nsosversion || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:47Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "enrolledby || nshardwareplatform || nsosversion || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:47Z DEBUG Updating managed permission: System: Manage Host Certificates 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Manage Host Certificates 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Manage Host Enrollment Password 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Manage Host Enrollment Password 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:48Z DEBUG Legacy permission Manage host keytab not found 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Manage Host Keytab 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Manage Host Keytab 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Manage Host Keytab Permissions 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Manage Host Keytab Permissions 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Manage Host Principals 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Manage Host Principals 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:48Z DEBUG Legacy permission Manage Host SSH Public Keys not found 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Manage Host SSH Public Keys 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Manage Host SSH Public Keys 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:48Z DEBUG Legacy permission Modify Hosts not found 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Modify Hosts 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Modify Hosts 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Read Host Compat Tree 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Read Host Compat Tree 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Read Host Membership 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Read Host Membership 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Read Hosts 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Read Hosts 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";)' to cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:48Z DEBUG Legacy permission Remove Hosts not found 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Remove Hosts 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Remove Hosts 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=computers,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:48Z DEBUG Updating managed permissions for hostgroup 2022-12-17T23:55:48Z DEBUG Legacy permission Add Hostgroups not found 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Add Hostgroups 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Add Hostgroups 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Add Hostgroups";allow (add) groupdn = "ldap:///cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Add Hostgroups";allow (add) groupdn = "ldap:///cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:48Z DEBUG Legacy permission Modify Hostgroup membership not found 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Modify Hostgroup Membership 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Modify Hostgroup Membership 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "member")(targetfilter = "(&(!(cn=ipaservers))(objectclass=ipahostgroup))")(version 3.0;acl "permission:System: Modify Hostgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "member")(targetfilter = "(&(!(cn=ipaservers))(objectclass=ipahostgroup))")(version 3.0;acl "permission:System: Modify Hostgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:48Z DEBUG Legacy permission Modify Hostgroups not found 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Modify Hostgroups 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Modify Hostgroups 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "cn || description || membermanager")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Modify Hostgroups";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || description || membermanager")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Modify Hostgroups";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Read Hostgroup Membership 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Read Hostgroup Membership 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "member || memberhost || memberof || memberuser")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroup Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "member || memberhost || memberof || memberuser")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroup Membership";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Read Hostgroups 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Read Hostgroups 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || membermanager || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroups";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || membermanager || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroups";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:48Z DEBUG Legacy permission Remove Hostgroups not found 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Remove Hostgroups 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Remove Hostgroups 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Remove Hostgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=hostgroups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Remove Hostgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:48Z DEBUG Updating managed permissions for idoverridegroup 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Read Group ID Overrides 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Read Group ID Overrides 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || gidnumber || ipaanchoruuid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaGroupOverride)")(version 3.0;acl "permission:System: Read Group ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)' to cn=views,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || gidnumber || ipaanchoruuid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaGroupOverride)")(version 3.0;acl "permission:System: Read Group ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:48Z DEBUG Updating managed permissions for idoverrideuser 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Read User ID Overrides 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Read User ID Overrides 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetattr = "createtimestamp || description || entryusn || gecos || gidnumber || homedirectory || ipaanchoruuid || ipaoriginaluid || ipasshpubkey || loginshell || memberof || modifytimestamp || objectclass || uid || uidnumber || usercertificate")(targetfilter = "(objectclass=ipaUserOverride)")(version 3.0;acl "permission:System: Read User ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)' to cn=views,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "createtimestamp || description || entryusn || gecos || gidnumber || homedirectory || ipaanchoruuid || ipaoriginaluid || ipasshpubkey || loginshell || memberof || modifytimestamp || objectclass || uid || uidnumber || usercertificate")(targetfilter = "(objectclass=ipaUserOverride)")(version 3.0;acl "permission:System: Read User ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:48Z DEBUG Updating managed permissions for idp 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Add External IdP server 2022-12-17T23:55:48Z DEBUG Updating ACI for managed permission: System: Add External IdP server 2022-12-17T23:55:48Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaidp)")(version 3.0;acl "permission:System: Add External IdP server";allow (add) groupdn = "ldap:///cn=System: Add External IdP server,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=idp,dc=redacted_domain,dc=com 2022-12-17T23:55:48Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipaidp)")(version 3.0;acl "permission:System: Add External IdP server";allow (add) groupdn = "ldap:///cn=System: Add External IdP server,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:48Z DEBUG Updating managed permission: System: Delete External IdP server 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Delete External IdP server 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaidp)")(version 3.0;acl "permission:System: Delete External IdP server";allow (delete) groupdn = "ldap:///cn=System: Delete External IdP server,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=idp,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipaidp)")(version 3.0;acl "permission:System: Delete External IdP server";allow (delete) groupdn = "ldap:///cn=System: Delete External IdP server,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Modify External IdP server 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Modify External IdP server 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "cn || ipaidpauthendpoint || ipaidpclientid || ipaidpclientsecret || ipaidpdevauthendpoint || ipaidpissuerurl || ipaidpkeysendpoint || ipaidpscope || ipaidpsub || ipaidptokenendpoint || ipaidpuserinfoendpoint || objectclass")(targetfilter = "(objectclass=ipaidp)")(version 3.0;acl "permission:System: Modify External IdP server";allow (write) groupdn = "ldap:///cn=System: Modify External IdP server,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=idp,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || ipaidpauthendpoint || ipaidpclientid || ipaidpclientsecret || ipaidpdevauthendpoint || ipaidpissuerurl || ipaidpkeysendpoint || ipaidpscope || ipaidpsub || ipaidptokenendpoint || ipaidpuserinfoendpoint || objectclass")(targetfilter = "(objectclass=ipaidp)")(version 3.0;acl "permission:System: Modify External IdP server";allow (write) groupdn = "ldap:///cn=System: Modify External IdP server,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read External IdP server 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read External IdP server 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipaidpauthendpoint || ipaidpclientid || ipaidpdevauthendpoint || ipaidpissuerurl || ipaidpkeysendpoint || ipaidpscope || ipaidpsub || ipaidptokenendpoint || ipaidpuserinfoendpoint || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidp)")(version 3.0;acl "permission:System: Read External IdP server";allow (compare,read,search) groupdn = "ldap:///cn=System: Read External IdP server,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=idp,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || ipaidpauthendpoint || ipaidpclientid || ipaidpdevauthendpoint || ipaidpissuerurl || ipaidpkeysendpoint || ipaidpscope || ipaidpsub || ipaidptokenendpoint || ipaidpuserinfoendpoint || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidp)")(version 3.0;acl "permission:System: Read External IdP server";allow (compare,read,search) groupdn = "ldap:///cn=System: Read External IdP server,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read External IdP server client secret 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read External IdP server client secret 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipaidpauthendpoint || ipaidpclientid || ipaidpclientsecret || ipaidpdevauthendpoint || ipaidpissuerurl || ipaidpkeysendpoint || ipaidpscope || ipaidpsub || ipaidptokenendpoint || ipaidpuserinfoendpoint || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidp)")(version 3.0;acl "permission:System: Read External IdP server client secret";allow (compare,read,search) groupdn = "ldap:///cn=System: Read External IdP server client secret,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=idp,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || ipaidpauthendpoint || ipaidpclientid || ipaidpclientsecret || ipaidpdevauthendpoint || ipaidpissuerurl || ipaidpkeysendpoint || ipaidpscope || ipaidpsub || ipaidptokenendpoint || ipaidpuserinfoendpoint || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidp)")(version 3.0;acl "permission:System: Read External IdP server client secret";allow (compare,read,search) groupdn = "ldap:///cn=System: Read External IdP server client secret,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permissions for idrange 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read ID Ranges 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read ID Ranges 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipaautoprivategroups || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ranges,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || ipaautoprivategroups || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permissions for idview 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read ID Views 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read ID Views 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || ipadomainresolutionorder || modifytimestamp || objectclass")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Read ID Views";allow (compare,read,search) userdn = "ldap:///all";)' to cn=views,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || ipadomainresolutionorder || modifytimestamp || objectclass")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Read ID Views";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permissions for krbtpolicy 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read Default Kerberos Ticket Policy 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read Default Kerberos Ticket Policy 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || krbauthindmaxrenewableage || krbauthindmaxticketlife || krbdefaultencsalttypes || krbmaxrenewableage || krbmaxticketlife || krbsupportedencsalttypes || modifytimestamp || objectclass")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read Default Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Default Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "createtimestamp || entryusn || krbauthindmaxrenewableage || krbauthindmaxticketlife || krbdefaultencsalttypes || krbmaxrenewableage || krbmaxticketlife || krbsupportedencsalttypes || modifytimestamp || objectclass")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read Default Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Default Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read User Kerberos Ticket Policy 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read User Kerberos Ticket Policy 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "krbauthindmaxrenewableage || krbauthindmaxticketlife || krbmaxrenewableage || krbmaxticketlife")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read User Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krbauthindmaxrenewableage || krbauthindmaxticketlife || krbmaxrenewableage || krbmaxticketlife")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read User Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permissions for location 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Add IPA Locations 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Add IPA Locations 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Add IPA Locations";allow (add) groupdn = "ldap:///cn=System: Add IPA Locations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=locations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Add IPA Locations";allow (add) groupdn = "ldap:///cn=System: Add IPA Locations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Modify IPA Locations 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Modify IPA Locations 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "description")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Modify IPA Locations";allow (write) groupdn = "ldap:///cn=System: Modify IPA Locations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=locations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "description")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Modify IPA Locations";allow (write) groupdn = "ldap:///cn=System: Modify IPA Locations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read IPA Locations 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read IPA Locations 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "createtimestamp || description || entryusn || idnsname || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Read IPA Locations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Locations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=locations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "createtimestamp || description || entryusn || idnsname || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Read IPA Locations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Locations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Remove IPA Locations 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Remove IPA Locations 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Remove IPA Locations";allow (delete) groupdn = "ldap:///cn=System: Remove IPA Locations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=locations,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Remove IPA Locations";allow (delete) groupdn = "ldap:///cn=System: Remove IPA Locations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permissions for netgroup 2022-12-17T23:55:49Z DEBUG Legacy permission Add netgroups not found 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Add Netgroups 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Add Netgroups 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Add Netgroups";allow (add) groupdn = "ldap:///cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=ng,cn=alt,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Add Netgroups";allow (add) groupdn = "ldap:///cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Legacy permission Modify netgroup membership not found 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Modify Netgroup Membership 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Modify Netgroup Membership 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "externalhost || member || memberhost || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=ng,cn=alt,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "externalhost || member || memberhost || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Legacy permission Modify netgroups not found 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Modify Netgroups 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Modify Netgroups 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "description")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroups";allow (write) groupdn = "ldap:///cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=ng,cn=alt,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "description")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroups";allow (write) groupdn = "ldap:///cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read Netgroup Compat Tree 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read Netgroup Compat Tree 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read Netgroup Membership 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read Netgroup Membership 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || externalhost || member || memberhost || memberof || memberuser || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ng,cn=alt,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "createtimestamp || entryusn || externalhost || member || memberhost || memberof || memberuser || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read Netgroups 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read Netgroups 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipauniqueid || modifytimestamp || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ng,cn=alt,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipauniqueid || modifytimestamp || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:49Z DEBUG Legacy permission Remove netgroups not found 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Remove Netgroups 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Remove Netgroups 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Remove Netgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=ng,cn=alt,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Remove Netgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permissions for otpconfig 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read OTP Configuration 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read OTP Configuration 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "cn || ipatokenhotpauthwindow || ipatokenhotpsyncwindow || ipatokentotpauthwindow || ipatokentotpsyncwindow")(targetfilter = "(objectclass=ipatokenotpconfig)")(version 3.0;acl "permission:System: Read OTP Configuration";allow (compare,read,search) userdn = "ldap:///all";)' to cn=otp,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "cn || ipatokenhotpauthwindow || ipatokenhotpsyncwindow || ipatokentotpauthwindow || ipatokentotpsyncwindow")(targetfilter = "(objectclass=ipatokenotpconfig)")(version 3.0;acl "permission:System: Read OTP Configuration";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permissions for permission 2022-12-17T23:55:49Z DEBUG Legacy permission Modify privilege membership not found 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Modify Privilege Membership 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Modify Privilege Membership 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "member")(targetfilter = "(objectclass=ipapermission)")(version 3.0;acl "permission:System: Modify Privilege Membership";allow (write) groupdn = "ldap:///cn=System: Modify Privilege Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "member")(targetfilter = "(objectclass=ipapermission)")(version 3.0;acl "permission:System: Modify Privilege Membership";allow (write) groupdn = "ldap:///cn=System: Modify Privilege Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read ACIs 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read ACIs 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read Permissions 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read Permissions 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipapermbindruletype || ipapermdefaultattr || ipapermexcludedattr || ipapermincludedattr || ipapermissiontype || ipapermlocation || ipapermright || ipapermtarget || ipapermtargetfilter || member || memberhost || memberof || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipapermission)")(version 3.0;acl "permission:System: Read Permissions";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Permissions,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=permissions,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipapermbindruletype || ipapermdefaultattr || ipapermexcludedattr || ipapermincludedattr || ipapermissiontype || ipapermlocation || ipapermright || ipapermtarget || ipapermtargetfilter || member || memberhost || memberof || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipapermission)")(version 3.0;acl "permission:System: Read Permissions";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Permissions,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permissions for privilege 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Add Privileges 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Add Privileges 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Add Privileges";allow (add) groupdn = "ldap:///cn=System: Add Privileges,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Add Privileges";allow (add) groupdn = "ldap:///cn=System: Add Privileges,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Modify Privileges 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Modify Privileges 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || description || o || ou || owner || seealso")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Modify Privileges";allow (write) groupdn = "ldap:///cn=System: Modify Privileges,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "businesscategory || cn || description || o || ou || owner || seealso")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Modify Privileges";allow (write) groupdn = "ldap:///cn=System: Modify Privileges,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read Privileges 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read Privileges 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || member || memberhost || memberof || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Read Privileges";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Privileges,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || member || memberhost || memberof || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Read Privileges";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Privileges,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Remove Privileges 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Remove Privileges 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Remove Privileges";allow (delete) groupdn = "ldap:///cn=System: Remove Privileges,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=privileges,cn=pbac,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Remove Privileges";allow (delete) groupdn = "ldap:///cn=System: Remove Privileges,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permissions for pwpolicy 2022-12-17T23:55:49Z DEBUG Legacy permission Add Group Password Policy not found 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Add Group Password Policy 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Add Group Password Policy 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetfilter = "(|(objectclass=ipapwdpolicy)(objectclass=krbpwdpolicy))")(version 3.0;acl "permission:System: Add Group Password Policy";allow (add) groupdn = "ldap:///cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(|(objectclass=ipapwdpolicy)(objectclass=krbpwdpolicy))")(version 3.0;acl "permission:System: Add Group Password Policy";allow (add) groupdn = "ldap:///cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Legacy permission Delete Group Password Policy not found 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Delete Group Password Policy 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Delete Group Password Policy 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetfilter = "(|(objectclass=ipapwdpolicy)(objectclass=krbpwdpolicy))")(version 3.0;acl "permission:System: Delete Group Password Policy";allow (delete) groupdn = "ldap:///cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(|(objectclass=ipapwdpolicy)(objectclass=krbpwdpolicy))")(version 3.0;acl "permission:System: Delete Group Password Policy";allow (delete) groupdn = "ldap:///cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Legacy permission Modify Group Password Policy not found 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Modify Group Password Policy 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Modify Group Password Policy 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "ipapwddictcheck || ipapwdmaxrepeat || ipapwdmaxsequence || ipapwdusercheck || krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength || passwordgracelimit")(targetfilter = "(|(objectclass=ipapwdpolicy)(objectclass=krbpwdpolicy))")(version 3.0;acl "permission:System: Modify Group Password Policy";allow (write) groupdn = "ldap:///cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipapwddictcheck || ipapwdmaxrepeat || ipapwdmaxsequence || ipapwdusercheck || krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength || passwordgracelimit")(targetfilter = "(|(objectclass=ipapwdpolicy)(objectclass=krbpwdpolicy))")(version 3.0;acl "permission:System: Modify Group Password Policy";allow (write) groupdn = "ldap:///cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read Group Password Policy 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read Group Password Policy 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "cn || cospriority || createtimestamp || entryusn || ipapwddictcheck || ipapwdmaxrepeat || ipapwdmaxsequence || ipapwdusercheck || krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength || modifytimestamp || objectclass || passwordgracelimit")(targetfilter = "(|(objectclass=ipapwdpolicy)(objectclass=krbpwdpolicy))")(version 3.0;acl "permission:System: Read Group Password Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=REDACTED_DOMAIN.COM,cn=kerberos,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || cospriority || createtimestamp || entryusn || ipapwddictcheck || ipapwdmaxrepeat || ipapwdmaxsequence || ipapwdusercheck || krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength || modifytimestamp || objectclass || passwordgracelimit")(targetfilter = "(|(objectclass=ipapwdpolicy)(objectclass=krbpwdpolicy))")(version 3.0;acl "permission:System: Read Group Password Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permissions for radiusproxy 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read Radius Servers 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read Radius Servers 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || ipatokenradiusretries || ipatokenradiusserver || ipatokenradiustimeout || ipatokenusermapattribute || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipatokenradiusconfiguration)")(version 3.0;acl "permission:System: Read Radius Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Radius Servers,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=radiusproxy,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || ipatokenradiusretries || ipatokenradiusserver || ipatokenradiustimeout || ipatokenusermapattribute || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipatokenradiusconfiguration)")(version 3.0;acl "permission:System: Read Radius Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Radius Servers,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permissions for realmdomains 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Modify Realm Domains 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Modify Realm Domains 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "associateddomain")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Modify Realm Domains";allow (write) groupdn = "ldap:///cn=System: Modify Realm Domains,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=Realm Domains,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "associateddomain")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Modify Realm Domains";allow (write) groupdn = "ldap:///cn=System: Modify Realm Domains,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read Realm Domains 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read Realm Domains 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "associateddomain || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Read Realm Domains";allow (compare,read,search) userdn = "ldap:///all";)' to cn=Realm Domains,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "associateddomain || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Read Realm Domains";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permissions for role 2022-12-17T23:55:49Z DEBUG Legacy permission Add Roles not found 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Add Roles 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Add Roles 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Add Roles";allow (add) groupdn = "ldap:///cn=System: Add Roles,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Add Roles";allow (add) groupdn = "ldap:///cn=System: Add Roles,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Legacy permission Modify Role membership not found 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Modify Role Membership 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Modify Role Membership 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "member")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Modify Role Membership";allow (write) groupdn = "ldap:///cn=System: Modify Role Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "member")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Modify Role Membership";allow (write) groupdn = "ldap:///cn=System: Modify Role Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Legacy permission Modify Roles not found 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Modify Roles 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Modify Roles 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "cn || description")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Modify Roles";allow (write) groupdn = "ldap:///cn=System: Modify Roles,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || description")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Modify Roles";allow (write) groupdn = "ldap:///cn=System: Modify Roles,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read Roles 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read Roles 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || member || memberhost || memberof || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Read Roles";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Roles,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || member || memberhost || memberof || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Read Roles";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Roles,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Legacy permission Remove Roles not found 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Remove Roles 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Remove Roles 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Remove Roles";allow (delete) groupdn = "ldap:///cn=System: Remove Roles,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=roles,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Remove Roles";allow (delete) groupdn = "ldap:///cn=System: Remove Roles,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permissions for selinuxusermap 2022-12-17T23:55:49Z DEBUG Legacy permission Add SELinux User Maps not found 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Add SELinux User Maps 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Add SELinux User Maps 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Add SELinux User Maps";allow (add) groupdn = "ldap:///cn=System: Add SELinux User Maps,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=usermap,cn=selinux,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Add SELinux User Maps";allow (add) groupdn = "ldap:///cn=System: Add SELinux User Maps,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Legacy permission Modify SELinux User Maps not found 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Modify SELinux User Maps 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Modify SELinux User Maps 2022-12-17T23:55:49Z DEBUG Adding ACI '(targetattr = "cn || ipaenabledflag || ipaselinuxuser || memberhost || memberuser || seealso")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Modify SELinux User Maps";allow (write) groupdn = "ldap:///cn=System: Modify SELinux User Maps,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=usermap,cn=selinux,dc=redacted_domain,dc=com 2022-12-17T23:55:49Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || ipaenabledflag || ipaselinuxuser || memberhost || memberuser || seealso")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Modify SELinux User Maps";allow (write) groupdn = "ldap:///cn=System: Modify SELinux User Maps,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:49Z DEBUG Updating managed permission: System: Read SELinux User Maps 2022-12-17T23:55:49Z DEBUG Updating ACI for managed permission: System: Read SELinux User Maps 2022-12-17T23:55:50Z DEBUG Adding ACI '(targetattr = "accesstime || cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipaselinuxuser || ipauniqueid || member || memberhost || memberuser || modifytimestamp || objectclass || seealso || usercategory")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Read SELinux User Maps";allow (compare,read,search) userdn = "ldap:///all";)' to cn=usermap,cn=selinux,dc=redacted_domain,dc=com 2022-12-17T23:55:50Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "accesstime || cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipaselinuxuser || ipauniqueid || member || memberhost || memberuser || modifytimestamp || objectclass || seealso || usercategory")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Read SELinux User Maps";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:50Z DEBUG Legacy permission Remove SELinux User Maps not found 2022-12-17T23:55:50Z DEBUG Updating managed permission: System: Remove SELinux User Maps 2022-12-17T23:55:50Z DEBUG Updating ACI for managed permission: System: Remove SELinux User Maps 2022-12-17T23:55:50Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Remove SELinux User Maps";allow (delete) groupdn = "ldap:///cn=System: Remove SELinux User Maps,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=usermap,cn=selinux,dc=redacted_domain,dc=com 2022-12-17T23:55:50Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Remove SELinux User Maps";allow (delete) groupdn = "ldap:///cn=System: Remove SELinux User Maps,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:50Z DEBUG Updating managed permissions for server 2022-12-17T23:55:50Z DEBUG Updating managed permission: System: Read Locations of IPA Servers 2022-12-17T23:55:50Z DEBUG Updating ACI for managed permission: System: Read Locations of IPA Servers 2022-12-17T23:55:50Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:50Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:50Z DEBUG Updating managed permission: System: Read Status of Services on IPA Servers 2022-12-17T23:55:50Z DEBUG Updating ACI for managed permission: System: Read Status of Services on IPA Servers 2022-12-17T23:55:50Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:50Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:50Z DEBUG Updating managed permissions for service 2022-12-17T23:55:50Z DEBUG Legacy permission Add Services not found 2022-12-17T23:55:50Z DEBUG Updating managed permission: System: Add Services 2022-12-17T23:55:50Z DEBUG Updating ACI for managed permission: System: Add Services 2022-12-17T23:55:50Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:50Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:50Z DEBUG Legacy permission Manage service keytab not found 2022-12-17T23:55:50Z DEBUG Updating managed permission: System: Manage Service Keytab 2022-12-17T23:55:50Z DEBUG Updating ACI for managed permission: System: Manage Service Keytab 2022-12-17T23:55:50Z DEBUG Adding ACI '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:50Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:50Z DEBUG Updating managed permission: System: Manage Service Keytab Permissions 2022-12-17T23:55:50Z DEBUG Updating ACI for managed permission: System: Manage Service Keytab Permissions 2022-12-17T23:55:50Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:50Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:50Z DEBUG Updating managed permission: System: Manage Service Principals 2022-12-17T23:55:50Z DEBUG Updating ACI for managed permission: System: Manage Service Principals 2022-12-17T23:55:50Z DEBUG Adding ACI '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:50Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:50Z DEBUG Legacy permission Modify Services not found 2022-12-17T23:55:50Z DEBUG Updating managed permission: System: Modify Services 2022-12-17T23:55:50Z DEBUG Updating ACI for managed permission: System: Modify Services 2022-12-17T23:55:50Z DEBUG Adding ACI '(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:50Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:50Z DEBUG Updating managed permission: System: Read POSIX details of SMB services 2022-12-17T23:55:50Z DEBUG Updating ACI for managed permission: System: Read POSIX details of SMB services 2022-12-17T23:55:50Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";)' to cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:50Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:50Z DEBUG Updating managed permission: System: Read Services 2022-12-17T23:55:50Z DEBUG Updating ACI for managed permission: System: Read Services 2022-12-17T23:55:50Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)' to cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:50Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:50Z DEBUG Legacy permission Remove Services not found 2022-12-17T23:55:50Z DEBUG Updating managed permission: System: Remove Services 2022-12-17T23:55:50Z DEBUG Updating ACI for managed permission: System: Remove Services 2022-12-17T23:55:50Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=services,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:50Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:50Z DEBUG Updating managed permissions for servicedelegationrule 2022-12-17T23:55:50Z DEBUG Updating managed permission: System: Add Service Delegations 2022-12-17T23:55:50Z DEBUG Updating ACI for managed permission: System: Add Service Delegations 2022-12-17T23:55:50Z DEBUG Adding ACI '(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Add Service Delegations";allow (add) groupdn = "ldap:///cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:50Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Add Service Delegations";allow (add) groupdn = "ldap:///cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:50Z DEBUG Updating managed permission: System: Modify Service Delegation Membership 2022-12-17T23:55:50Z DEBUG Updating ACI for managed permission: System: Modify Service Delegation Membership 2022-12-17T23:55:50Z DEBUG Adding ACI '(targetattr = "ipaallowedtarget || memberprincipal")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Modify Service Delegation Membership";allow (write) groupdn = "ldap:///cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:50Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipaallowedtarget || memberprincipal")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Modify Service Delegation Membership";allow (write) groupdn = "ldap:///cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:50Z DEBUG Updating managed permission: System: Read Service Delegations 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Read Service Delegations 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipaallowedtarget || memberprincipal || modifytimestamp || objectclass")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Read Service Delegations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || ipaallowedtarget || memberprincipal || modifytimestamp || objectclass")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Read Service Delegations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Remove Service Delegations 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Remove Service Delegations 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Remove Service Delegations";allow (delete) groupdn = "ldap:///cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=s4u2proxy,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Remove Service Delegations";allow (delete) groupdn = "ldap:///cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permissions for servicedelegationtarget 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Add Service Delegations 2022-12-17T23:55:51Z DEBUG No changes to permission: System: Add Service Delegations 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Modify Service Delegation Membership 2022-12-17T23:55:51Z DEBUG No changes to permission: System: Modify Service Delegation Membership 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Read Service Delegations 2022-12-17T23:55:51Z DEBUG No changes to permission: System: Read Service Delegations 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Remove Service Delegations 2022-12-17T23:55:51Z DEBUG No changes to permission: System: Remove Service Delegations 2022-12-17T23:55:51Z DEBUG Updating managed permissions for stageuser 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Add Stage User 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Add Stage User 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Modify Preserved Users 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Modify Preserved Users 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Modify Stage User 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Modify Stage User 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Modify User RDN 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Modify User RDN 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "uid")(target = "ldap:///uid=*,cn=users,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify User RDN";allow (write) groupdn = "ldap:///cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "uid")(target = "ldap:///uid=*,cn=users,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify User RDN";allow (write) groupdn = "ldap:///cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Preserve User 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Preserve User 2022-12-17T23:55:51Z DEBUG Adding ACI '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(target_from = "ldap:///cn=users,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(target_from = "ldap:///cn=users,cn=accounts,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Read Preserved Users 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Read Preserved Users 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Read Stage User password 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Read Stage User password 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Read Stage Users 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Read Stage Users 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Remove Stage User 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Remove Stage User 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Remove preserved User 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Remove preserved User 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Reset Preserved User password 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Reset Preserved User password 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Undelete User 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Undelete User 2022-12-17T23:55:51Z DEBUG Adding ACI '(target_to = "ldap:///cn=users,cn=accounts,dc=redacted_domain,dc=com")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(target_to = "ldap:///cn=users,cn=accounts,dc=redacted_domain,dc=com")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permissions for subid 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Manage Subordinate Ids 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Manage Subordinate Ids 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "description || ipaowner")(targetfilter = "(objectclass=ipasubordinateidentry)")(version 3.0;acl "permission:System: Manage Subordinate Ids";allow (write) groupdn = "ldap:///cn=System: Manage Subordinate Ids,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=subids,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "description || ipaowner")(targetfilter = "(objectclass=ipasubordinateidentry)")(version 3.0;acl "permission:System: Manage Subordinate Ids";allow (write) groupdn = "ldap:///cn=System: Manage Subordinate Ids,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Read Subordinate Id Attributes 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Read Subordinate Id Attributes 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "createtimestamp || description || entryusn || ipaowner || ipasubgidcount || ipasubgidnumber || ipasubuidcount || ipasubuidnumber || ipauniqueid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipasubordinateidentry)")(version 3.0;acl "permission:System: Read Subordinate Id Attributes";allow (compare,read,search) userdn = "ldap:///all";)' to cn=subids,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "createtimestamp || description || entryusn || ipaowner || ipasubgidcount || ipasubgidnumber || ipasubuidcount || ipasubuidnumber || ipauniqueid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipasubordinateidentry)")(version 3.0;acl "permission:System: Read Subordinate Id Attributes";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Read Subordinate Id Count 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Read Subordinate Id Count 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "numsubordinates")(target = "ldap:///cn=subids,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read Subordinate Id Count";allow (compare,read,search) userdn = "ldap:///all";)' to cn=subids,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "numsubordinates")(target = "ldap:///cn=subids,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read Subordinate Id Count";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Remove Subordinate Ids 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Remove Subordinate Ids 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipasubordinateidentry)")(version 3.0;acl "permission:System: Remove Subordinate Ids";allow (delete) groupdn = "ldap:///cn=System: Remove Subordinate Ids,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=subids,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipasubordinateidentry)")(version 3.0;acl "permission:System: Remove Subordinate Ids";allow (delete) groupdn = "ldap:///cn=System: Remove Subordinate Ids,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permissions for sudocmd 2022-12-17T23:55:51Z DEBUG Legacy permission Add Sudo command not found 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Add Sudo Command 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Add Sudo Command 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Add Sudo Command";allow (add) groupdn = "ldap:///cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=sudocmds,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Add Sudo Command";allow (add) groupdn = "ldap:///cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Legacy permission Delete Sudo command not found 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Delete Sudo Command 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Delete Sudo Command 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Delete Sudo Command";allow (delete) groupdn = "ldap:///cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=sudocmds,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Delete Sudo Command";allow (delete) groupdn = "ldap:///cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Legacy permission Modify Sudo command not found 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Modify Sudo Command 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Modify Sudo Command 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "description")(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Modify Sudo Command";allow (write) groupdn = "ldap:///cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=sudocmds,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "description")(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Modify Sudo Command";allow (write) groupdn = "ldap:///cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Read Sudo Commands 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Read Sudo Commands 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "createtimestamp || description || entryusn || ipauniqueid || memberof || modifytimestamp || objectclass || sudocmd")(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Read Sudo Commands";allow (compare,read,search) userdn = "ldap:///all";)' to cn=sudocmds,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "createtimestamp || description || entryusn || ipauniqueid || memberof || modifytimestamp || objectclass || sudocmd")(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Read Sudo Commands";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permissions for sudocmdgroup 2022-12-17T23:55:51Z DEBUG Legacy permission Add Sudo command group not found 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Add Sudo Command Group 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Add Sudo Command Group 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Add Sudo Command Group";allow (add) groupdn = "ldap:///cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=sudocmdgroups,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Add Sudo Command Group";allow (add) groupdn = "ldap:///cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Legacy permission Delete Sudo command group not found 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Delete Sudo Command Group 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Delete Sudo Command Group 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Delete Sudo Command Group";allow (delete) groupdn = "ldap:///cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=sudocmdgroups,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Delete Sudo Command Group";allow (delete) groupdn = "ldap:///cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Legacy permission Manage Sudo command group membership not found 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Manage Sudo Command Group Membership 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Manage Sudo Command Group Membership 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "member")(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Manage Sudo Command Group Membership";allow (write) groupdn = "ldap:///cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=sudocmdgroups,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "member")(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Manage Sudo Command Group Membership";allow (write) groupdn = "ldap:///cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Modify Sudo Command Group 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Modify Sudo Command Group 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "description")(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Modify Sudo Command Group";allow (write) groupdn = "ldap:///cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=sudocmdgroups,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "description")(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Modify Sudo Command Group";allow (write) groupdn = "ldap:///cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Read Sudo Command Groups 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Read Sudo Command Groups 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || member || memberhost || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Read Sudo Command Groups";allow (compare,read,search) userdn = "ldap:///all";)' to cn=sudocmdgroups,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || member || memberhost || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Read Sudo Command Groups";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:51Z DEBUG Updating managed permissions for sudorule 2022-12-17T23:55:51Z DEBUG Legacy permission Add Sudo rule not found 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Add Sudo rule 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Add Sudo rule 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Add Sudo rule";allow (add) groupdn = "ldap:///cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=sudorules,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(2, 'aci', [b'(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Add Sudo rule";allow (add) groupdn = "ldap:///cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:51Z DEBUG Legacy permission Delete Sudo rule not found 2022-12-17T23:55:51Z DEBUG Updating managed permission: System: Delete Sudo rule 2022-12-17T23:55:51Z DEBUG Updating ACI for managed permission: System: Delete Sudo rule 2022-12-17T23:55:51Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Delete Sudo rule";allow (delete) groupdn = "ldap:///cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=sudorules,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:51Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Delete Sudo rule";allow (delete) groupdn = "ldap:///cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Legacy permission Modify Sudo rule not found 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Modify Sudo rule 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Modify Sudo rule 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "cmdcategory || description || externalhost || externaluser || hostcategory || hostmask || ipaenabledflag || ipasudoopt || ipasudorunas || ipasudorunasextgroup || ipasudorunasextuser || ipasudorunasextusergroup || ipasudorunasgroup || ipasudorunasgroupcategory || ipasudorunasusercategory || memberallowcmd || memberdenycmd || memberhost || memberuser || sudonotafter || sudonotbefore || sudoorder || usercategory")(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Modify Sudo rule";allow (write) groupdn = "ldap:///cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=sudorules,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cmdcategory || description || externalhost || externaluser || hostcategory || hostmask || ipaenabledflag || ipasudoopt || ipasudorunas || ipasudorunasextgroup || ipasudorunasextuser || ipasudorunasextusergroup || ipasudorunasgroup || ipasudorunasgroupcategory || ipasudorunasusercategory || memberallowcmd || memberdenycmd || memberhost || memberuser || sudonotafter || sudonotbefore || sudoorder || usercategory")(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Modify Sudo rule";allow (write) groupdn = "ldap:///cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read Sudo Rules 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read Sudo Rules 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "cmdcategory || cn || createtimestamp || description || entryusn || externalhost || externaluser || hostcategory || hostmask || ipaenabledflag || ipasudoopt || ipasudorunas || ipasudorunasextgroup || ipasudorunasextuser || ipasudorunasextusergroup || ipasudorunasgroup || ipasudorunasgroupcategory || ipasudorunasusercategory || ipauniqueid || member || memberallowcmd || memberdenycmd || memberhost || memberuser || modifytimestamp || objectclass || sudonotafter || sudonotbefore || sudoorder || usercategory")(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Read Sudo Rules";allow (compare,read,search) userdn = "ldap:///all";)' to cn=sudorules,cn=sudo,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cmdcategory || cn || createtimestamp || description || entryusn || externalhost || externaluser || hostcategory || hostmask || ipaenabledflag || ipasudoopt || ipasudorunas || ipasudorunasextgroup || ipasudorunasextuser || ipasudorunasextusergroup || ipasudorunasgroup || ipasudorunasgroupcategory || ipasudorunasusercategory || ipauniqueid || member || memberallowcmd || memberdenycmd || memberhost || memberuser || modifytimestamp || objectclass || sudonotafter || sudonotbefore || sudoorder || usercategory")(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Read Sudo Rules";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read Sudoers compat tree 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read Sudoers compat tree 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permissions for trust 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read Trust Information 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read Trust Information 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)' to cn=trusts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read system trust accounts 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read system trust accounts 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=trusts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permissions for user 2022-12-17T23:55:52Z DEBUG Legacy permission Add user to default group not found 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Add User to default group 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Add User to default group 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "member")(target = "ldap:///cn=ipausers,cn=groups,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Add User to default group";allow (write) groupdn = "ldap:///cn=System: Add User to default group,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=groups,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "member")(target = "ldap:///cn=ipausers,cn=groups,cn=accounts,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Add User to default group";allow (write) groupdn = "ldap:///cn=System: Add User to default group,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Legacy permission Add Users not found 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Add Users 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Add Users 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Add Users";allow (add) groupdn = "ldap:///cn=System: Add Users,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Add Users";allow (add) groupdn = "ldap:///cn=System: Add Users,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Change Admin User password 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Change Admin User password 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "krbpasswordexpiration || krbprincipalkey || passwordhistory || sambalmpassword || sambantpassword || userpassword")(targetfilter = "(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com)")(version 3.0;acl "permission:System: Change Admin User password";allow (write) groupdn = "ldap:///cn=System: Change Admin User password,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krbpasswordexpiration || krbprincipalkey || passwordhistory || sambalmpassword || sambantpassword || userpassword")(targetfilter = "(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com)")(version 3.0;acl "permission:System: Change Admin User password";allow (write) groupdn = "ldap:///cn=System: Change Admin User password,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Legacy permission Change a user password not found 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Change User password 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Change User password 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "krbpasswordexpiration || krbprincipalkey || passwordhistory || sambalmpassword || sambantpassword || userpassword")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Change User password";allow (write) groupdn = "ldap:///cn=System: Change User password,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krbpasswordexpiration || krbprincipalkey || passwordhistory || sambalmpassword || sambantpassword || userpassword")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Change User password";allow (write) groupdn = "ldap:///cn=System: Change User password,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Manage User Certificate Mappings 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Manage User Certificate Mappings 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "ipacertmapdata || objectclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificate Mappings";allow (write) groupdn = "ldap:///cn=System: Manage User Certificate Mappings,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipacertmapdata || objectclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificate Mappings";allow (write) groupdn = "ldap:///cn=System: Manage User Certificate Mappings,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Manage User Certificates 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Manage User Certificates 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "usercertificate")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Manage User Certificates";allow (write) groupdn = "ldap:///cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "usercertificate")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Manage User Certificates";allow (write) groupdn = "ldap:///cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Manage User Principals 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Manage User Principals 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Manage User Principals";allow (write) groupdn = "ldap:///cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Manage User Principals";allow (write) groupdn = "ldap:///cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Legacy permission Manage User SSH Public Keys not found 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Manage User SSH Public Keys 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Manage User SSH Public Keys 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "ipasshpubkey")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Manage User SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipasshpubkey")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Manage User SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Legacy permission Modify Users not found 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Modify Users 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Modify Users 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "businesscategory || carlicense || cn || departmentnumber || description || displayname || employeenumber || employeetype || facsimiletelephonenumber || gecos || givenname || homedirectory || homephone || inetuserhttpurl || initials || l || labeleduri || loginshell || mail || manager || mepmanagedentry || mobile || objectclass || ou || pager || postalcode || preferredlanguage || roomnumber || secretary || seealso || sn || st || street || telephonenumber || title || userclass")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Modify Users";allow (write) groupdn = "ldap:///cn=System: Modify Users,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "businesscategory || carlicense || cn || departmentnumber || description || displayname || employeenumber || employeetype || facsimiletelephonenumber || gecos || givenname || homedirectory || homephone || inetuserhttpurl || initials || l || labeleduri || loginshell || mail || manager || mepmanagedentry || mobile || objectclass || ou || pager || postalcode || preferredlanguage || roomnumber || secretary || seealso || sn || st || street || telephonenumber || title || userclass")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Modify Users";allow (write) groupdn = "ldap:///cn=System: Modify Users,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read UPG Definition 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read UPG Definition 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "*")(target = "ldap:///cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read UPG Definition";allow (compare,read,search) groupdn = "ldap:///cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "*")(target = "ldap:///cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read UPG Definition";allow (compare,read,search) groupdn = "ldap:///cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read User Addressbook Attributes 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read User Addressbook Attributes 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "audio || businesscategory || carlicense || departmentnumber || destinationindicator || employeenumber || employeetype || facsimiletelephonenumber || homephone || homepostaladdress || inetuserhttpurl || inetuserstatus || internationalisdnnumber || ipacertmapdata || jpegphoto || l || labeleduri || mail || mobile || o || ou || pager || photo || physicaldeliveryofficename || postaladdress || postalcode || postofficebox || preferreddeliverymethod || preferredlanguage || registeredaddress || roomnumber || secretary || seealso || st || street || telephonenumber || teletexterminalidentifier || telexnumber || usercertificate || usersmimecertificate || x121address || x500uniqueidentifier")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Addressbook Attributes";allow (compare,read,search) userdn = "ldap:///all";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "audio || businesscategory || carlicense || departmentnumber || destinationindicator || employeenumber || employeetype || facsimiletelephonenumber || homephone || homepostaladdress || inetuserhttpurl || inetuserstatus || internationalisdnnumber || ipacertmapdata || jpegphoto || l || labeleduri || mail || mobile || o || ou || pager || photo || physicaldeliveryofficename || postaladdress || postalcode || postofficebox || preferreddeliverymethod || preferredlanguage || registeredaddress || roomnumber || secretary || seealso || st || street || telephonenumber || teletexterminalidentifier || telexnumber || usercertificate || usersmimecertificate || x121address || x500uniqueidentifier")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Addressbook Attributes";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read User Compat Tree 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read User Compat Tree 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read User IPA Attributes 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read User IPA Attributes 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "ipasshpubkey || ipauniqueid || ipauserauthtype || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User IPA Attributes";allow (compare,read,search) userdn = "ldap:///all";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipasshpubkey || ipauniqueid || ipauserauthtype || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User IPA Attributes";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read User Kerberos Attributes 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read User Kerberos Attributes 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalexpiration || krbprincipalname || krbprincipaltype || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Attributes";allow (compare,read,search) userdn = "ldap:///all";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalexpiration || krbprincipalname || krbprincipaltype || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Attributes";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read User Kerberos Login Attributes 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read User Kerberos Login Attributes 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "krblastadminunlock || krblastfailedauth || krblastpwdchange || krblastsuccessfulauth || krbloginfailedcount || krbpwdpolicyreference || krbticketpolicyreference || krbupenabled")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Login Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krblastadminunlock || krblastfailedauth || krblastpwdchange || krblastsuccessfulauth || krbloginfailedcount || krbpwdpolicyreference || krbticketpolicyreference || krbupenabled")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Login Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read User Membership 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read User Membership 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "memberof")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "memberof")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Membership";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read User NT Attributes 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read User NT Attributes 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "ntuniqueid || ntuseracctexpires || ntusercodepage || ntuserdeleteaccount || ntuserdomainid || ntuserlastlogoff || ntuserlastlogon")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User NT Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User NT Attributes,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ntuniqueid || ntuseracctexpires || ntusercodepage || ntuserdeleteaccount || ntuserdomainid || ntuserlastlogoff || ntuserlastlogon")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User NT Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User NT Attributes,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read User Standard Attributes 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read User Standard Attributes 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || initials || ipantsecurityidentifier || loginshell || manager || modifytimestamp || objectclass || sn || title || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Standard Attributes";allow (compare,read,search) userdn = "ldap:///anyone";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || initials || ipantsecurityidentifier || loginshell || manager || modifytimestamp || objectclass || sn || title || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Standard Attributes";allow (compare,read,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read User Views Compat Tree 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read User Views Compat Tree 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=redacted_domain,dc=com")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:52Z DEBUG Legacy permission Remove Users not found 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Remove Users 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Remove Users 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Remove Users";allow (delete) groupdn = "ldap:///cn=System: Remove Users,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Remove Users";allow (delete) groupdn = "ldap:///cn=System: Remove Users,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Legacy permission Unlock user accounts not found 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Unlock User 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Unlock User 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "krblastadminunlock || krbloginfailedcount || nsaccountlock")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Unlock User";allow (write) groupdn = "ldap:///cn=System: Unlock User,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=users,cn=accounts,dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "krblastadminunlock || krbloginfailedcount || nsaccountlock")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=redacted_domain,dc=com))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Unlock User";allow (write) groupdn = "ldap:///cn=System: Unlock User,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permissions for vault 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Add Vaults 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Add Vaults 2022-12-17T23:55:52Z DEBUG Adding ACI '(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Delete Vaults 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Delete Vaults 2022-12-17T23:55:52Z DEBUG Adding ACI '(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Manage Vault Membership 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Manage Vault Membership 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Manage Vault Ownership 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Manage Vault Ownership 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Modify Vaults 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Modify Vaults 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Read Vaults 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Read Vaults 2022-12-17T23:55:52Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:52Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:52Z DEBUG Updating managed permissions for vaultcontainer 2022-12-17T23:55:52Z DEBUG Updating managed permission: System: Add Vault Containers 2022-12-17T23:55:52Z DEBUG Updating ACI for managed permission: System: Add Vault Containers 2022-12-17T23:55:53Z DEBUG Adding ACI '(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Delete Vault Containers 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Delete Vault Containers 2022-12-17T23:55:53Z DEBUG Adding ACI '(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Manage Vault Container Ownership 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Manage Vault Container Ownership 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Modify Vault Containers 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Modify Vault Containers 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Read Vault Containers 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Read Vault Containers 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:53Z DEBUG Updating non-object managed permissions 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Add CA Certificate For Renewal 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Add CA Certificate For Renewal 2022-12-17T23:55:53Z DEBUG Adding ACI '(target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Add CA Certificate For Renewal";allow (add) groupdn = "ldap:///cn=System: Add CA Certificate For Renewal,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(2, 'aci', [b'(target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Add CA Certificate For Renewal";allow (add) groupdn = "ldap:///cn=System: Add CA Certificate For Renewal,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Add Certificate Store Entry 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Add Certificate Store Entry 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Compat Tree ID View targets 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Compat Tree ID View targets 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Modify CA Certificate 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Modify CA Certificate 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "cacertificate")(targetfilter = "(objectclass=pkica)")(version 3.0;acl "permission:System: Modify CA Certificate";allow (write) groupdn = "ldap:///cn=System: Modify CA Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=CAcert,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "cacertificate")(targetfilter = "(objectclass=pkica)")(version 3.0;acl "permission:System: Modify CA Certificate";allow (write) groupdn = "ldap:///cn=System: Modify CA Certificate,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Modify CA Certificate For Renewal 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Modify CA Certificate For Renewal 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "usercertificate")(target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Modify CA Certificate For Renewal";allow (write) groupdn = "ldap:///cn=System: Modify CA Certificate For Renewal,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "usercertificate")(target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Modify CA Certificate For Renewal";allow (write) groupdn = "ldap:///cn=System: Modify CA Certificate For Renewal,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Modify Certificate Store Entry 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Modify Certificate Store Entry 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Read AD Domains 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Read AD Domains 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipantdomainguid || ipantfallbackprimarygroup || ipantflatname || ipantsecurityidentifier || modifytimestamp || objectclass")(target = "ldap:///cn=ad,cn=etc,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipantdomainattrs)")(version 3.0;acl "permission:System: Read AD Domains";allow (compare,read,search) userdn = "ldap:///all";)' to cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || ipantdomainguid || ipantfallbackprimarygroup || ipantflatname || ipantsecurityidentifier || modifytimestamp || objectclass")(target = "ldap:///cn=ad,cn=etc,dc=redacted_domain,dc=com")(targetfilter = "(objectclass=ipantdomainattrs)")(version 3.0;acl "permission:System: Read AD Domains";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Read CA Certificate 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Read CA Certificate 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "authorityrevocationlist || cacertificate || certificaterevocationlist || cn || createtimestamp || crosscertificatepair || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=pkica)")(version 3.0;acl "permission:System: Read CA Certificate";allow (compare,read,search) userdn = "ldap:///anyone";)' to cn=CAcert,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "authorityrevocationlist || cacertificate || certificaterevocationlist || cn || createtimestamp || crosscertificatepair || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=pkica)")(version 3.0;acl "permission:System: Read CA Certificate";allow (compare,read,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Read CA Renewal Information 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Read CA Renewal Information 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Read CA Renewal Information";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ca_renewal,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Read CA Renewal Information";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Read Certificate Store Entries 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Read Certificate Store Entries 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";)' to cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Read DNA Configuration 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Read DNA Configuration 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || dnahostname || dnaportnum || dnaremainingvalues || dnaremotebindmethod || dnaremoteconnprotocol || dnasecureportnum || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=dnasharedconfig)")(version 3.0;acl "permission:System: Read DNA Configuration";allow (compare,read,search) userdn = "ldap:///all";)' to cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "cn || createtimestamp || dnahostname || dnaportnum || dnaremainingvalues || dnaremotebindmethod || dnaremoteconnprotocol || dnasecureportnum || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=dnasharedconfig)")(version 3.0;acl "permission:System: Read DNA Configuration";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Read DUA Profile 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Read DUA Profile 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "attributemap || authenticationmethod || bindtimelimit || cn || createtimestamp || credentiallevel || defaultsearchbase || defaultsearchscope || defaultserverlist || dereferencealiases || entryusn || followreferrals || modifytimestamp || objectclass || objectclassmap || ou || preferredserverlist || profilettl || searchtimelimit || serviceauthenticationmethod || servicecredentiallevel || servicesearchdescriptor")(targetfilter = "(|(objectclass=organizationalUnit)(objectclass=DUAConfigProfile))")(version 3.0;acl "permission:System: Read DUA Profile";allow (compare,read,search) userdn = "ldap:///anyone";)' to ou=profile,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "attributemap || authenticationmethod || bindtimelimit || cn || createtimestamp || credentiallevel || defaultsearchbase || defaultsearchscope || defaultserverlist || dereferencealiases || entryusn || followreferrals || modifytimestamp || objectclass || objectclassmap || ou || preferredserverlist || profilettl || searchtimelimit || serviceauthenticationmethod || servicecredentiallevel || servicesearchdescriptor")(targetfilter = "(|(objectclass=organizationalUnit)(objectclass=DUAConfigProfile))")(version 3.0;acl "permission:System: Read DUA Profile";allow (compare,read,search) userdn = "ldap:///anyone";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Read Domain Level 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Read Domain Level 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "createtimestamp || entryusn || ipadomainlevel || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipadomainlevelconfig)")(version 3.0;acl "permission:System: Read Domain Level";allow (compare,read,search) userdn = "ldap:///all";)' to cn=Domain Level,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "createtimestamp || entryusn || ipadomainlevel || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipadomainlevelconfig)")(version 3.0;acl "permission:System: Read Domain Level";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Read IPA Masters 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Read IPA Masters 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=masters,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Read Replication Information 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Read Replication Information 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicachangecount || nsds5replicacleanruv || nsds5replicaid || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicatombstonepurgeinterval || nsds5replicatype || nsds5task || nsstate || objectclass")(targetfilter = "(objectclass=nsds5replica)")(version 3.0;acl "permission:System: Read Replication Information";allow (compare,read,search) userdn = "ldap:///all";)' to cn=replication,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(2, 'aci', [b'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicachangecount || nsds5replicacleanruv || nsds5replicaid || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicatombstonepurgeinterval || nsds5replicatype || nsds5task || nsstate || objectclass")(targetfilter = "(objectclass=nsds5replica)")(version 3.0;acl "permission:System: Read Replication Information";allow (compare,read,search) userdn = "ldap:///all";)'])] 2022-12-17T23:55:53Z DEBUG Updating managed permission: System: Remove Certificate Store Entry 2022-12-17T23:55:53Z DEBUG Updating ACI for managed permission: System: Remove Certificate Store Entry 2022-12-17T23:55:53Z DEBUG Adding ACI '(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)' to cn=certificates,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(0, 'aci', [b'(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=redacted_domain,dc=com";)'])] 2022-12-17T23:55:53Z DEBUG Deleting obsolete permission System: Read Timestamp and USN Operational Attributes 2022-12-17T23:55:53Z DEBUG raw: permission_del(('System: Read Timestamp and USN Operational Attributes',), force=True, version='2.101') 2022-12-17T23:55:53Z DEBUG permission_del(('System: Read Timestamp and USN Operational Attributes',), continue=False, force=True, version='2.101') 2022-12-17T23:55:53Z DEBUG Obsolete permission not found 2022-12-17T23:55:53Z DEBUG Deleting obsolete permission System: Read Creator and Modifier Operational Attributes 2022-12-17T23:55:53Z DEBUG raw: permission_del(('System: Read Creator and Modifier Operational Attributes',), force=True, version='2.101') 2022-12-17T23:55:53Z DEBUG permission_del(('System: Read Creator and Modifier Operational Attributes',), continue=False, force=True, version='2.101') 2022-12-17T23:55:53Z DEBUG Obsolete permission not found 2022-12-17T23:55:53Z DEBUG Executing upgrade plugin: update_read_replication_agreements_permission 2022-12-17T23:55:53Z DEBUG raw: update_read_replication_agreements_permission 2022-12-17T23:55:53Z DEBUG Old permission not found 2022-12-17T23:55:53Z DEBUG Executing upgrade plugin: update_idrange_baserid 2022-12-17T23:55:53Z DEBUG raw: update_idrange_baserid 2022-12-17T23:55:53Z DEBUG update_idrange_baserid: search for ipa-ad-trust-posix ID ranges with ipaBaseRID != 0 2022-12-17T23:55:53Z DEBUG update_idrange_baserid: no AD domain range with posix attributes found 2022-12-17T23:55:53Z DEBUG Executing upgrade plugin: update_passync_privilege_update 2022-12-17T23:55:53Z DEBUG raw: update_passync_privilege_update 2022-12-17T23:55:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:53Z DEBUG Add PassSync user as a member of PassSync privilege 2022-12-17T23:55:53Z DEBUG PassSync user not found, no update needed 2022-12-17T23:55:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:53Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:53Z DEBUG Executing upgrade plugin: update_dnsserver_configuration_into_ldap 2022-12-17T23:55:53Z DEBUG raw: update_dnsserver_configuration_into_ldap 2022-12-17T23:55:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:53Z DEBUG DNS container not found, nothing to upgrade 2022-12-17T23:55:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:53Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:53Z DEBUG Executing upgrade plugin: update_ldap_server_list 2022-12-17T23:55:53Z DEBUG raw: update_ldap_server_list 2022-12-17T23:55:53Z DEBUG Executing upgrade plugin: update_dna_shared_config 2022-12-17T23:55:53Z DEBUG raw: update_dna_shared_config 2022-12-17T23:55:53Z DEBUG Found DNA config cn=posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:53Z DEBUG dnaSharedCfgDN: cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(2, 'dnaRemoteConnProtocol', [b'LDAP']), (2, 'dnaRemoteBindMethod', [b'SASL/GSSAPI'])] 2022-12-17T23:55:53Z DEBUG Updated entry dnaHostname=master.redacted_domain.com+dnaPortNum=389,cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(2, 'dnaRemoteConnProtocol', [b'LDAP']), (2, 'dnaRemoteBindMethod', [b'SASL/GSSAPI'])] 2022-12-17T23:55:53Z DEBUG Updated entry dnaHostname=master.redacted_domain.com+dnaPortNum=0,cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG Found DNA config cn=Subordinate IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2022-12-17T23:55:53Z DEBUG dnaSharedCfgDN: cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(2, 'dnaRemoteConnProtocol', [b'LDAP']), (2, 'dnaRemoteBindMethod', [b'SASL/GSSAPI'])] 2022-12-17T23:55:53Z DEBUG Updated entry dnaHostname=master.redacted_domain.com+dnaPortNum=389,cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG update_entry modlist [(2, 'dnaRemoteConnProtocol', [b'LDAP']), (2, 'dnaRemoteBindMethod', [b'SASL/GSSAPI'])] 2022-12-17T23:55:53Z DEBUG Updated entry dnaHostname=master.redacted_domain.com+dnaPortNum=0,cn=subordinate-ids,cn=dna,cn=ipa,cn=etc,dc=redacted_domain,dc=com 2022-12-17T23:55:53Z DEBUG Executing upgrade plugin: update_unhashed_password 2022-12-17T23:55:53Z DEBUG raw: update_unhashed_password 2022-12-17T23:55:53Z DEBUG Upgrading unhashed password configuration 2022-12-17T23:55:53Z DEBUG Unhashed password this is not a winsync deployment 2022-12-17T23:55:53Z DEBUG Executing upgrade plugin: update_krb_uri_txt_records_for_locations 2022-12-17T23:55:53Z DEBUG raw: update_krb_uri_txt_records_for_locations 2022-12-17T23:55:53Z DEBUG LDAP update duration: /usr/share/ipa/updates/90-post_upgrade_plugins.update 8.715 sec 2022-12-17T23:55:53Z DEBUG Destroyed connection context.ldap2_140472247965264 2022-12-17T23:55:53Z DEBUG step duration: dirsrv __upgrade 15.68 sec 2022-12-17T23:55:53Z DEBUG [8/10]: stopping directory server 2022-12-17T23:55:53Z DEBUG Destroyed connection context.ldap2_140472260056272 2022-12-17T23:55:53Z DEBUG Starting external process 2022-12-17T23:55:53Z DEBUG args=['/bin/systemctl', 'stop', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:55:54Z DEBUG Process finished, return code=0 2022-12-17T23:55:54Z DEBUG stdout= 2022-12-17T23:55:54Z DEBUG stderr= 2022-12-17T23:55:54Z DEBUG Stop of dirsrv@REDACTED_DOMAIN-COM.service complete 2022-12-17T23:55:54Z DEBUG step duration: dirsrv __stop_instance 1.59 sec 2022-12-17T23:55:54Z DEBUG [9/10]: restoring configuration 2022-12-17T23:55:54Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:54Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:54Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:54Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:55Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:55Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:55Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:55Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:55Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:55Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:55Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:55Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:55Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:55Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:55Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:55:55Z DEBUG step duration: dirsrv __restore_config 0.08 sec 2022-12-17T23:55:55Z DEBUG [10/10]: starting directory server 2022-12-17T23:55:55Z DEBUG Starting external process 2022-12-17T23:55:55Z DEBUG args=['/bin/systemctl', 'start', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:55:59Z DEBUG Process finished, return code=0 2022-12-17T23:55:59Z DEBUG stdout= 2022-12-17T23:55:59Z DEBUG stderr= 2022-12-17T23:55:59Z DEBUG Start of dirsrv@REDACTED_DOMAIN-COM.service complete 2022-12-17T23:55:59Z DEBUG Created connection context.ldap2_140472260056272 2022-12-17T23:55:59Z DEBUG step duration: dirsrv __start 4.22 sec 2022-12-17T23:55:59Z DEBUG Done. 2022-12-17T23:55:59Z DEBUG service duration: dirsrv 25.07 sec 2022-12-17T23:55:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:59Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:59Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:55:59Z DEBUG Restarting the KDC 2022-12-17T23:55:59Z DEBUG Starting external process 2022-12-17T23:55:59Z DEBUG args=['/bin/systemctl', 'restart', 'krb5kdc.service'] 2022-12-17T23:55:59Z DEBUG Process finished, return code=0 2022-12-17T23:55:59Z DEBUG stdout= 2022-12-17T23:55:59Z DEBUG stderr= 2022-12-17T23:55:59Z DEBUG Starting external process 2022-12-17T23:55:59Z DEBUG args=['/bin/systemctl', 'is-active', 'krb5kdc.service'] 2022-12-17T23:55:59Z DEBUG Process finished, return code=0 2022-12-17T23:55:59Z DEBUG stdout=active 2022-12-17T23:55:59Z DEBUG stderr= 2022-12-17T23:55:59Z DEBUG Restart of krb5kdc.service complete 2022-12-17T23:56:01Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:56:01Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:56:01Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:56:01Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:56:01Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:56:01Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:56:01Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:56:01Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:56:01Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:56:02Z DEBUG Created connection context.ldap2_139969608432400 2022-12-17T23:56:02Z DEBUG Custodia client for '' with promotion no. 2022-12-17T23:56:02Z DEBUG Custodia uses LDAPI. 2022-12-17T23:56:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:56:02Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:56:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:56:02Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:56:02Z DEBUG Trying to find certificate subject base in sysupgrade 2022-12-17T23:56:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:56:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-17T23:56:02Z DEBUG Found certificate subject base in sysupgrade: O=REDACTED_DOMAIN.COM 2022-12-17T23:56:02Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:56:02Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:56:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:56:02Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:56:02Z DEBUG Starting external process 2022-12-17T23:56:02Z DEBUG args=['pki-server', 'subsystem-show', 'kra'] 2022-12-17T23:56:03Z DEBUG Process finished, return code=1 2022-12-17T23:56:03Z DEBUG stdout= 2022-12-17T23:56:03Z DEBUG stderr=ERROR: ERROR: No kra subsystem in instance pki-tomcat. 2022-12-17T23:56:03Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:56:03Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:56:03Z DEBUG Starting external process 2022-12-17T23:56:03Z DEBUG args=['pki-server', 'subsystem-show', 'ca'] 2022-12-17T23:56:03Z DEBUG Process finished, return code=0 2022-12-17T23:56:03Z DEBUG stdout= Subsystem ID: ca Instance ID: pki-tomcat Enabled: True 2022-12-17T23:56:03Z DEBUG stderr= 2022-12-17T23:56:03Z DEBUG Configuring KRA server (pki-tomcatd). Estimated time: 2 minutes 2022-12-17T23:56:03Z DEBUG [1/9]: configuring KRA instance 2022-12-17T23:56:03Z DEBUG Trying to find the certificate for the admin user 2022-12-17T23:56:03Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:56:03Z DEBUG Contents of pkispawn configuration file (/tmp/tmpqkpfdwjh): [KRA] pki_admin_cert_file = /root/.dogtag/pki-tomcat/ca_admin.cert pki_admin_cert_request_type = pkcs10 pki_admin_dualkey = False pki_admin_email = root@localhost pki_admin_name = admin pki_admin_nickname = ipa-ca-agent pki_admin_password = XXXXXXXX pki_admin_subject_dn = cn=ipa-ca-agent,O=REDACTED_DOMAIN.COM pki_admin_uid = admin pki_ajp_secret = 3Wzn03EyEp0QeAkAFG5nCcXU123dnRFfsj6SZfCHxgmA pki_audit_group = pkiaudit pki_audit_signing_key_algorithm = SHA256withRSA pki_audit_signing_key_size = 2048 pki_audit_signing_key_type = rsa pki_audit_signing_nickname = auditSigningCert cert-pki-kra pki_audit_signing_signing_algorithm = SHA256withRSA pki_audit_signing_subject_dn = cn=KRA Audit,O=REDACTED_DOMAIN.COM pki_audit_signing_token = internal pki_backup_keys = True pki_backup_password = XXXXXXXX pki_ca_hostname = master.redacted_domain.com pki_ca_port = 443 pki_ca_signing_cert_path = /etc/pki/pki-tomcat/external_ca.cert pki_ca_signing_nickname = caSigningCert cert-pki-ca pki_cert_chain_nickname = caSigningCert External CA pki_cert_chain_path = /etc/pki/pki-tomcat/external_ca_chain.cert pki_client_admin_cert_p12 = /tmp/tmpyyq6fqgn pki_client_database_dir = /var/lib/ipa/tmp-dvglda_f pki_client_database_password = XXXXXXXX pki_client_database_purge = True pki_client_dir = /root/.dogtag/pki-tomcat pki_client_pkcs12_password = XXXXXXXX pki_configuration_path = /etc/pki pki_dns_domainname = redacted_domain.com pki_ds_base_dn = o=kra,o=ipaca pki_ds_bind_dn = cn=Directory Manager pki_ds_create_new_db = False pki_ds_database = ipaca pki_ds_hostname = master.redacted_domain.com pki_ds_ldap_port = 389 pki_ds_ldaps_port = 636 pki_ds_password = XXXXXXXX pki_ds_remove_data = True pki_ds_secure_connection = True pki_ds_secure_connection_ca_nickname = Directory Server CA certificate pki_ds_secure_connection_ca_pem_file = /etc/ipa/ca.crt pki_enable_proxy = True pki_existing = False pki_external_step_two = False pki_group = pkiuser pki_hostname = master.redacted_domain.com pki_hsm_enable = False pki_hsm_libfile = pki_hsm_modulename = pki_import_admin_cert = False pki_instance_configuration_path = /etc/pki/pki-tomcat pki_instance_name = pki-tomcat pki_issuing_ca = https://master.redacted_domain.com:443 pki_issuing_ca_hostname = master.redacted_domain.com pki_issuing_ca_https_port = 443 pki_issuing_ca_uri = https://master.redacted_domain.com:443 pki_key_id_generator = legacy pki_kra_ephemeral_requests = True pki_pkcs12_password = pki_pkcs12_path = pki_replication_password = pki_request_id_generator = legacy pki_san_for_server_cert = pki_san_inject = False pki_security_domain_hostname = master.redacted_domain.com pki_security_domain_https_port = 443 pki_security_domain_name = IPA pki_security_domain_password = XXXXXXXX pki_security_domain_user = admin pki_self_signed_token = internal pki_share_db = True pki_share_dbuser_dn = uid=pkidbuser,ou=people,o=ipaca pki_skip_configuration = False pki_skip_ds_verify = False pki_skip_installation = False pki_skip_sd_verify = False pki_sslserver_key_algorithm = SHA256withRSA pki_sslserver_key_size = 2048 pki_sslserver_key_type = rsa pki_sslserver_nickname = Server-Cert cert-pki-ca pki_sslserver_subject_dn = cn=master.redacted_domain.com,O=REDACTED_DOMAIN.COM pki_sslserver_token = internal pki_standalone = False pki_status_request_timeout = 15 pki_storage_key_algorithm = SHA256withRSA pki_storage_key_size = 2048 pki_storage_key_type = rsa pki_storage_nickname = storageCert cert-pki-kra pki_storage_signing_algorithm = SHA256withRSA pki_storage_subject_dn = cn=KRA Storage Certificate,O=REDACTED_DOMAIN.COM pki_storage_token = internal pki_subsystem = KRA pki_subsystem_key_algorithm = SHA256withRSA pki_subsystem_key_size = 2048 pki_subsystem_key_type = rsa pki_subsystem_nickname = subsystemCert cert-pki-ca pki_subsystem_subject_dn = cn=CA Subsystem,O=REDACTED_DOMAIN.COM pki_subsystem_token = internal pki_subsystem_type = kra pki_theme_enable = True pki_theme_server_dir = /usr/share/pki/common-ui pki_token_name = internal pki_transport_key_algorithm = SHA256withRSA pki_transport_key_size = 2048 pki_transport_key_type = rsa pki_transport_nickname = transportCert cert-pki-kra pki_transport_signing_algorithm = SHA256withRSA pki_transport_subject_dn = cn=KRA Transport Certificate,O=REDACTED_DOMAIN.COM pki_transport_token = internal pki_user = pkiuser 2022-12-17T23:56:03Z DEBUG Starting external process 2022-12-17T23:56:03Z DEBUG args=['/usr/sbin/pkispawn', '-s', 'KRA', '-f', '/tmp/tmpqkpfdwjh', '--debug', '--log-file', '/var/log/pki/pki-kra-spawn.20221218005603.log'] 2022-12-17T23:58:11Z DEBUG Process finished, return code=0 2022-12-17T23:58:11Z DEBUG stdout=--------------- Export complete --------------- Loading deployment configuration from /tmp/tmpqkpfdwjh. Installation log: /var/log/pki/pki-kra-spawn.20221218005603.log Installing KRA into /var/lib/pki/pki-tomcat. ========================================================================== INSTALLATION SUMMARY ========================================================================== Administrator's username: admin Administrator's PKCS #12 file: /tmp/tmpyyq6fqgn To check the status of the subsystem: systemctl status pki-tomcatd@pki-tomcat.service To restart the subsystem: systemctl restart pki-tomcatd@pki-tomcat.service The URL for the subsystem is: https://master.redacted_domain.com:8443/kra PKI instances will be enabled upon system boot ========================================================================== 2022-12-17T23:58:11Z DEBUG stderr=INFO: Connecting to LDAP server at ldaps://master.redacted_domain.com:636 INFO: Connecting to LDAP server at ldaps://master.redacted_domain.com:636 INFO: Connecting to security domain at https://master.redacted_domain.com:443 INFO: Getting security domain info INFO: BEGIN spawning KRA subsystem in pki-tomcat instance INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /etc/pki/pki-tomcat/tomcat.conf INFO: Loading password config: /etc/pki/pki-tomcat/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser INFO: Setting up pkiuser group INFO: Reusing existing pkiuser group with GID 17 INFO: Setting up pkiuser user INFO: Reusing existing pkiuser user with UID 17 DEBUG: Retrieving UID for 'pkiuser' DEBUG: UID of 'pkiuser' is 17 DEBUG: Retrieving GID for 'pkiuser' DEBUG: GID of 'pkiuser' is 17 INFO: Initialization INFO: Setting up infrastructure INFO: Creating /etc/sysconfig/pki/tomcat/pki-tomcat INFO: Creating /etc/sysconfig/pki/tomcat/pki-tomcat/kra DEBUG: Command: mkdir -p /etc/sysconfig/pki/tomcat/pki-tomcat/kra DEBUG: Command: chmod 770 /etc/sysconfig/pki/tomcat/pki-tomcat/kra DEBUG: Command: chown 17:17 /etc/sysconfig/pki/tomcat/pki-tomcat/kra INFO: Creating /etc/sysconfig/pki/tomcat/pki-tomcat/kra/default.cfg DEBUG: Command: cp -p /usr/share/pki/server/etc/default.cfg /etc/sysconfig/pki/tomcat/pki-tomcat/kra/default.cfg DEBUG: Command: chmod 660 /etc/sysconfig/pki/tomcat/pki-tomcat/kra/default.cfg DEBUG: Command: chown 17:17 /etc/sysconfig/pki/tomcat/pki-tomcat/kra/default.cfg DEBUG: Command: touch /etc/sysconfig/pki/tomcat/pki-tomcat/kra/deployment.cfg DEBUG: Command: chmod 660 /etc/sysconfig/pki/tomcat/pki-tomcat/kra/deployment.cfg DEBUG: Command: chown 17:17 /etc/sysconfig/pki/tomcat/pki-tomcat/kra/deployment.cfg INFO: Creating /var/lib/pki/pki-tomcat INFO: Creating /var/lib/pki/pki-tomcat/kra DEBUG: Command: mkdir -p /var/lib/pki/pki-tomcat/kra DEBUG: Command: chmod 770 /var/lib/pki/pki-tomcat/kra DEBUG: Command: chown 17:17 /var/lib/pki/pki-tomcat/kra INFO: Preparing pki-tomcat instance INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /etc/pki/pki-tomcat/tomcat.conf INFO: Loading password config: /etc/pki/pki-tomcat/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser INFO: Creating /etc/pki/pki-tomcat INFO: Creating /etc/pki/pki-tomcat WARNING: Directory already exists: /etc/pki/pki-tomcat INFO: Creating /etc/pki/pki-tomcat/password.conf INFO: Reusing server NSS database password INFO: Using specified internal database password INFO: Reusing replication manager password INFO: Installing pki-tomcat instance INFO: Creating KRA subsystem INFO: Creating /var/log/pki/pki-tomcat/kra DEBUG: Command: mkdir /var/log/pki/pki-tomcat/kra INFO: Creating /var/log/pki/pki-tomcat/kra/archive DEBUG: Command: mkdir /var/log/pki/pki-tomcat/kra/archive INFO: Creating /var/log/pki/pki-tomcat/kra/signedAudit DEBUG: Command: mkdir /var/log/pki/pki-tomcat/kra/signedAudit INFO: Creating /etc/pki/pki-tomcat/kra DEBUG: Command: mkdir /etc/pki/pki-tomcat/kra INFO: Creating /etc/pki/pki-tomcat/kra/CS.cfg DEBUG: Command: cp /usr/share/pki/kra/conf/CS.cfg /etc/pki/pki-tomcat/kra/CS.cfg INFO: Creating /etc/pki/pki-tomcat/kra/registry.cfg INFO: Creating /var/lib/pki/pki-tomcat/kra/conf DEBUG: Command: ln -s /etc/pki/pki-tomcat/kra /var/lib/pki/pki-tomcat/kra/conf INFO: Creating /var/lib/pki/pki-tomcat/kra/logs DEBUG: Command: ln -s /var/log/pki/pki-tomcat/kra /var/lib/pki/pki-tomcat/kra/logs INFO: Creating /var/lib/pki/pki-tomcat/kra/registry DEBUG: Command: ln -s /etc/sysconfig/pki/tomcat/pki-tomcat /var/lib/pki/pki-tomcat/kra/registry INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /etc/pki/pki-tomcat/tomcat.conf INFO: Loading password config: /etc/pki/pki-tomcat/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/kra/conf/CS.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser DEBUG: PKISubsystem.get_subsystem_cert(transport) INFO: Getting transport cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(storage) INFO: Getting storage cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(sslserver) INFO: Getting sslserver cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(subsystem) INFO: Getting subsystem cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(audit_signing) INFO: Getting audit_signing cert info from CS.cfg INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/kra/conf/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/kra/conf/registry.cfg INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /etc/pki/pki-tomcat/tomcat.conf INFO: Loading password config: /etc/pki/pki-tomcat/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/kra/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/kra/conf/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser INFO: Creating password file: /etc/pki/pki-tomcat/pfile INFO: Updating /etc/pki/pki-tomcat/password.conf DEBUG: Command: chmod 660 /etc/pki/pki-tomcat/password.conf DEBUG: Command: chown 17:17 /etc/pki/pki-tomcat/password.conf INFO: Creating /var/lib/pki/pki-tomcat/kra/alias DEBUG: Command: ln -s /var/lib/pki/pki-tomcat/alias /var/lib/pki/pki-tomcat/kra/alias INFO: Removing /etc/pki/pki-tomcat/pfile DEBUG: Command: rm -f /etc/pki/pki-tomcat/pfile DEBUG: PKISubsystem.get_subsystem_cert(transport) INFO: Getting transport cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(storage) INFO: Getting storage cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(sslserver) INFO: Getting sslserver cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(subsystem) INFO: Getting subsystem cert info from CS.cfg DEBUG: PKISubsystem.get_subsystem_cert(audit_signing) INFO: Getting audit_signing cert info from CS.cfg INFO: Injecting SAN: False INFO: SSL server cert SAN: INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/kra/conf/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/kra/conf/registry.cfg INFO: Creating /root/.dogtag/pki-tomcat/kra DEBUG: Command: mkdir -p /root/.dogtag/pki-tomcat/kra DEBUG: Command: chmod 755 /root/.dogtag/pki-tomcat/kra DEBUG: Command: chown 0:0 /root/.dogtag/pki-tomcat/kra INFO: Creating password file: /root/.dogtag/pki-tomcat/kra/password.conf INFO: Updating /root/.dogtag/pki-tomcat/kra/password.conf DEBUG: Command: chmod 660 /root/.dogtag/pki-tomcat/kra/password.conf DEBUG: Command: chown 0:0 /root/.dogtag/pki-tomcat/kra/password.conf INFO: Storing PKCS #12 password in /root/.dogtag/pki-tomcat/kra/pkcs12_password.conf INFO: Updating /root/.dogtag/pki-tomcat/kra/pkcs12_password.conf DEBUG: Command: chmod 660 /root/.dogtag/pki-tomcat/kra/pkcs12_password.conf DEBUG: Command: chown 17:17 /root/.dogtag/pki-tomcat/kra/pkcs12_password.conf WARNING: Directory already exists: /var/lib/ipa/tmp-dvglda_f DEBUG: Command: certutil -N -d /var/lib/ipa/tmp-dvglda_f -f /root/.dogtag/pki-tomcat/kra/password.conf INFO: Creating SELinux contexts INFO: Generating system keys INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /etc/pki/pki-tomcat/tomcat.conf INFO: Loading password config: /etc/pki/pki-tomcat/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/kra/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/kra/conf/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser INFO: Configuring subsystem INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /etc/pki/pki-tomcat/tomcat.conf INFO: Loading password config: /etc/pki/pki-tomcat/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/kra/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/kra/conf/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser DEBUG: Setting ephemeral requests to true INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/kra/conf/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/kra/conf/registry.cfg INFO: Importing sslserver cert data from CA INFO: Importing subsystem cert data from CA INFO: Importing sslserver request data from CA INFO: Importing subsystem request data from CA INFO: Joining existing domain INFO: Searching for master.redacted_domain.com:443 INFO: - master.redacted_domain.com:443 INFO: Getting install token INFO: Using CA at https://master.redacted_domain.com:443 INFO: Retrieving CA certificate chain from https://master.redacted_domain.com:443 DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -f /etc/pki/pki-tomcat/password.conf -U https://master.redacted_domain.com:443 --ignore-cert-status UNTRUSTED_ISSUER --ignore-banner ca-cert-signing-export --pkcs7 --debug INFO: Connecting to https://master.redacted_domain.com:443 INFO: HTTP request: GET /pki/rest/info HTTP/1.1 INFO: Accept: application/json INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: INFO: Server certificate: CN=master.redacted_domain.com,O=REDACTED_DOMAIN.COM INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:56:13 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Set-Cookie: JSESSIONID=B92C61C7922BB28DB2F4E78C009D42BF; Path=/pki; Secure; HttpOnly INFO: Content-Type: application/json INFO: Content-Length: 50 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=100 INFO: Connection: Keep-Alive FINE: Response: {"Version":"11.2.0","Attributes":{"Attribute":[]}} INFO: Server Name: null INFO: Server Version: 11.2.0 INFO: Gettting CA signing certificate chain through REST service INFO: HTTP request: GET /ca/rest/config/cert/signing HTTP/1.1 INFO: Accept: application/json INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:56:13 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Cache-Control: no-transform, max-age=1000 INFO: ETag: "471007129" INFO: Content-Type: application/json INFO: Content-Length: 3595 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=99 INFO: Connection: Keep-Alive FINE: Response: {"id":"0x1","IssuerDN":"CN=Certificate Authority,O=REDACTED_DOMAIN.COM","SubjectDN":"CN=Certificate Authority,O=REDACTED_DOMAIN.COM","Encoded":"-----BEGIN CERTIFICATE-----\nMIIElzCCAv+gAwIBAgIBATANBgkqhkiG9w0BAQsFADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5D\r\nT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzUyMjdaFw00MjEy\r\nMTcyMzUyMjdaMDoxGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEeMBwGA1UEAwwVQ2VydGlmaWNh\r\ndGUgQXV0aG9yaXR5MIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEApvkK92tmgf6gzc7Y\r\nvEOKeMIM2vA4ib/aZYGjNA/rs6KKAKc9ZA3WWi/jmiskXCA6iidKX0EEBtlwYiC/mmRV5CG61/JG\r\n7s68OK0SIxHQi0Li2yKrbeGjFlcveJuM0baTGS3bA995lbiqGNfKNl1LoLGTJs7QPA/NAhX6xqTD\r\n91W35ueYO8n5G2rAlgyQAGGvBntFeZeH6tA4DrZkHzBgSe/YZkllAN4hJ0QOiBHvibSYjvvHE/Xh\r\nILTZ5ZkPdxZQ8f9LwYH7v8mELmG2BjX9ipE3QgBuZ1F+ntmHGyX68ReF2j8Mq98Ja1r88Uxg7Bel\r\ny1GCFtN1883pwM8cYH786LeN5ELaR1UPzrHCqWJs5P1aGFcUtaVHhJV1TrA9ifXdj9LOyUVrBRzj\r\njqysLYUB9O1f81qXGZwOF2My603PCN6wpQTxDULNjiSH7oDGTIZ30n5zf0X7WoBprvcTH3hP23Cz\r\nJUuIKvgDtLyiwJIVBlbBeEUa/HtBm55HxmYDBGihAgMBAAGjgacwgaQwHwYDVR0jBBgwFoAUnCHM\r\n6adwr08G/ZX+WF9+wfZnocYwDwYDVR0TAQH/BAUwAwEB/zAOBgNVHQ8BAf8EBAMCAcYwHQYDVR0O\r\nBBYEFJwhzOmncK9PBv2V/lhffsH2Z6HGMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0\r\ncDovL2lwYS1jYS5tb25pdmFncm91cC5jb20vY2Evb2NzcDANBgkqhkiG9w0BAQsFAAOCAYEAmk/N\r\nzYQfLywaP+vwIQxW7csqgWymAanHwHEwQa4nGs3be80jYPyr9u8x2yStxX93o5U3IwHyzMprSN5V\r\nehUT4RuFwzMaAscI3cjTtn0IL0GTEjeTMtUYvhj6bNg58tS1RRYDqUcI4Ug5r/KjPxfcTVDh7/XS\r\nX1MDgWwbf092Sx7+3OnBwxvkgk4xYthwRVfsPOT4UG5Wiad2q149ZYDWhzf+Kwft5hBoY1ZSvxoN\r\nzXjXP5ch25ObVpmw03OYFLWtMDfcsKJim+VvS0EN9TvYPqcLYzkfEfPn4kGwg/1+oz6zT6ODkfAd\r\nePqF3FqVD93ZqlX6o6R0jILJ+lLVDhKD9hZ/tJE/1JnBjdIuXzGQgzCayXCpSIkoDYVDtxFHp5p0\r\ns5Xm3kcci9bmB9P8XtlVQ25ha2fMl4/cWzI5U9kn7NSrksxBqlwLYf3ffCZ6bkBwBzto6xst4grB\r\nqvDy1xusxEafx6+VZAxH5ep/2YvBzDDclc5WvZ447jL6iPS+P9lT\r\n-----END CERTIFICATE-----\n","PKCS7CertChain":"MIIEygYJKoZIhvcNAQcCoIIEuzCCBLcCAQExADAPBgkqhkiG9w0BBwGgAgQAoIIEmzCCBJcwggL/oAMCAQICAQEwDQYJKoZIhvcNAQELBQAwOjEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMR4wHAYDVQQDDBVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcNMjIxMjE3MjM1MjI3WhcNNDIxMjE3MjM1MjI3WjA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAKb5CvdrZoH+oM3O2LxDinjCDNrwOIm/2mWBozQP67OiigCnPWQN1lov45orJFwgOoonSl9BBAbZcGIgv5pkVeQhutfyRu7OvDitEiMR0ItC4tsiq23hoxZXL3ibjNG2kxkt2wPfeZW4qhjXyjZdS6CxkybO0DwPzQIV+sakw/dVt+bnmDvJ+RtqwJYMkABhrwZ7RXmXh+rQOA62ZB8wYEnv2GZJZQDeISdEDogR74m0mI77xxP14SC02eWZD3cWUPH/S8GB+7/JhC5htgY1/YqRN0IAbmdRfp7Zhxsl+vEXhdo/DKvfCWta/PFMYOwXpctRghbTdfPN6cDPHGB+/Oi3jeRC2kdVD86xwqlibOT9WhhXFLWlR4SVdU6wPYn13Y/SzslFawUc446srC2FAfTtX/NalxmcDhdjMutNzwjesKUE8Q1CzY4kh+6AxkyGd9J+c39F+1qAaa73Ex94T9twsyVLiCr4A7S8osCSFQZWwXhFGvx7QZueR8ZmAwRooQIDAQABo4GnMIGkMB8GA1UdIwQYMBaAFJwhzOmncK9PBv2V/lhffsH2Z6HGMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgHGMB0GA1UdDgQWBBScIczpp3CvTwb9lf5YX37B9mehxjBBBggrBgEFBQcBAQQ1MDMwMQYIKwYBBQUHMAGGJWh0dHA6Ly9pcGEtY2EubW9uaXZhZ3JvdXAuY29tL2NhL29jc3AwDQYJKoZIhvcNAQELBQADggGBAJpPzc2EHy8sGj/r8CEMVu3LKoFspgGpx8BxMEGuJxrN23vNI2D8q/bvMdskrcV/d6OVNyMB8szKa0jeVXoVE+EbhcMzGgLHCN3I07Z9CC9BkxI3kzLVGL4Y+mzYOfLUtUUWA6lHCOFIOa/yoz8X3E1Q4e/10l9TA4FsG39Pdkse/tzpwcMb5IJOMWLYcEVX7Dzk+FBuVomndqtePWWA1oc3/isH7eYQaGNWUr8aDc141z+XIduTm1aZsNNzmBS1rTA33LCiYpvlb0tBDfU72D6nC2M5HxHz5+JBsIP9fqM+s0+jg5HwHXj6hdxalQ/d2apV+qOkdIyCyfpS1Q4Sg/YWf7SRP9SZwY3SLl8xkIMwmslwqUiJKA2FQ7cRR6eadLOV5t5HHIvW5gfT/F7ZVUNuYWtnzJeP3FsyOVPZJ+zUq5LMQapcC2H933wmem5AcAc7aOsbLeIKwarw8tcbrMRGn8evlWQMR+Xqf9mLwcww3JXOVr2eOO4y+oj0vj/ZUzEA","NotBefore":"Sun Dec 18 00:52:27 CET 2022","NotAfter":"Thu Dec 18 00:52:27 CET 2042"} INFO: Importing CA certificate chain DEBUG: NSSDatabase.import_pkcs7() DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmphf6uhn29/internal_password.txt pkcs7-import --trust CT,C,C --debug INFO: Loading PKCS #7 data from standard input INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token INFO: - CN=Certificate Authority,O=REDACTED_DOMAIN.COM INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/kra/conf/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/kra/conf/registry.cfg INFO: Emptying existing database DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/kra/webapps/kra/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI kra-db-empty --force --debug FINE: SubsystemDBEmptyCLI: Loading /var/lib/pki/pki-tomcat/kra/conf/CS.cfg INFO: Emptying database ipaca FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:636 with basic auth as cn=Directory Manager FINE: ldapconn/PKISocketFactory.makeSSLSocket: begins FINE: PKIClientSocketListener.handshakeCompleted: begins FINE: PKIClientSocketListener: Handshake completed: FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_ESTABLISH FINE: SSL handshake happened INFO: Entry not found: o=kra,o=ipaca FINE: PKIClientSocketListener.alertReceived: begins FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert received: FINE: - reason: clientAlertReceived: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: PKIClientSocketListener.alertSent: begins FINE: PKIClientSocketListener.alertSent: got description:0 FINE: PKIClientSocketListener.alertSent: got reason:clientAlertSent: CLOSE_NOTIFY FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert sent: FINE: - reason: clientAlertSent: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - subject: SYSTEM FINE: - server port: 636 INFO: Initializing database INFO: - internaldb.ldapconn.port: 636 INFO: - internaldb.ldapconn.secureConn: true DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/kra/webapps/kra/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI kra-db-init --setup-schema --create-base --create-containers --debug FINE: SubsystemDBInitCLI: Loading /var/lib/pki/pki-tomcat/kra/conf/CS.cfg INFO: Initializing database ipaca for o=kra,o=ipaca FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:636 with basic auth as cn=Directory Manager FINE: ldapconn/PKISocketFactory.makeSSLSocket: begins FINE: PKIClientSocketListener.handshakeCompleted: begins FINE: PKIClientSocketListener: Handshake completed: FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_ESTABLISH FINE: SSL handshake happened INFO: Initialize database INFO: Importing /usr/share/pki/server/conf/database.ldif FINE: - database: ipaca FINE: - rootSuffix: o=kra,o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-10673359732044117400.ldif INFO: Replacing nsslapd-maxbersize in cn=config INFO: Replacing nsslapd-pluginenabled in cn=USN,cn=plugins,cn=config INFO: Adding ou=csusers,cn=config INFO: Unable to add ou=csusers,cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Setting up PKI schema INFO: Importing /usr/share/pki/server/conf/schema.ldif INFO: Adding attributetypes: ( usertype-oid NAME 'usertype' DESC 'Distinguish whether the user is administrator, agent or subsystem.' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( userstate-oid NAME 'userstate' DESC 'Distinguish whether the user is administrator, agent or subsystem.' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( cmsuser-oid NAME 'cmsuser' DESC 'CMS User' SUP top STRUCTURAL MUST usertype MAY userstate X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( archivedBy-oid NAME 'archivedBy' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( adminMessages-oid NAME 'adminMessages' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( algorithm-oid NAME 'algorithm' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( algorithmId-oid NAME 'algorithmId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( signingAlgorithmId-oid NAME 'signingAlgorithmId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( autoRenew-oid NAME 'autoRenew' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( certStatus-oid NAME 'certStatus' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlName-oid NAME 'crlName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlSize-oid NAME 'crlSize' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( deltaSize-oid NAME 'deltaSize' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlNumber-oid NAME 'crlNumber' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( deltaNumber-oid NAME 'deltaNumber' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( firstUnsaved-oid NAME 'firstUnsaved' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlCache-oid NAME 'crlCache' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( revokedCerts-oid NAME 'revokedCerts' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( unrevokedCerts-oid NAME 'unrevokedCerts' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( expiredCerts-oid NAME 'expiredCerts' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( crlExtensions-oid NAME 'crlExtensions' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfArchival-oid NAME 'dateOfArchival' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfRecovery-oid NAME 'dateOfRecovery' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfRevocation-oid NAME 'dateOfRevocation' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfCreate-oid NAME 'dateOfCreate' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfModify-oid NAME 'dateOfModify' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( duration-oid NAME 'duration' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( extension-oid NAME 'extension' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( issuedBy-oid NAME 'issuedBy' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( issueInfo-oid NAME 'issueInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( issuerName-oid NAME 'issuerName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( keySize-oid NAME 'keySize' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( clientId-oid NAME 'clientId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dataType-oid NAME 'dataType' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( status-oid NAME 'status' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( keyState-oid NAME 'keyState' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( metaInfo-oid NAME 'metaInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( nextUpdate-oid NAME 'nextUpdate' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( notAfter-oid NAME 'notAfter' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( notBefore-oid NAME 'notBefore' DESC 'CMS defined attribute'SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( ownerName-oid NAME 'ownerName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( password-oid NAME 'password' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( p12Expiration-oid NAME 'p12Expiration' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( proofOfArchival-oid NAME 'proofOfArchival' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( publicKeyData-oid NAME 'publicKeyData' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( publicKeyFormat-oid NAME 'publicKeyFormat' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( privateKeyData-oid NAME 'privateKeyData' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestId-oid NAME 'requestId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestInfo-oid NAME 'requestInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestState-oid NAME 'requestState' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestResult-oid NAME 'requestResult' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestOwner-oid NAME 'requestOwner' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestAgentGroup-oid NAME 'requestAgentGroup' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestSourceId-oid NAME 'requestSourceId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestType-oid NAME 'requestType' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestFlag-oid NAME 'requestFlag' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( requestError-oid NAME 'requestError' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( resourceACLS-oid NAME 'resourceACLS' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( revInfo-oid NAME 'revInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( revokedBy-oid NAME 'revokedBy' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( revokedOn-oid NAME 'revokedOn' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( serialno-oid NAME 'serialno' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( nextRange-oid NAME 'nextRange' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( publishingStatus-oid NAME 'publishingStatus' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( beginRange-oid NAME 'beginRange' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( endRange-oid NAME 'endRange' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( subjectName-oid NAME 'subjectName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( sessionContext-oid NAME 'sessionContext' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.5 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( thisUpdate-oid NAME 'thisUpdate' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( transId-oid NAME 'transId' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( transStatus-oid NAME 'transStatus' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( transName-oid NAME 'transName' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( transOps-oid NAME 'transOps' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( userDN-oid NAME 'userDN' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( userMessages-oid NAME 'userMessages' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( version-oid NAME 'version' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( Clone-oid NAME 'Clone' SYNTAX 1.3.6.1.4.1.1466.115.121.1.7 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( DomainManager-oid NAME 'DomainManager' SYNTAX 1.3.6.1.4.1.1466.115.121.1.7 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SecurePort-oid NAME 'SecurePort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SecureAgentPort-oid NAME 'SecureAgentPort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SecureAdminPort-oid NAME 'SecureAdminPort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SecureEEClientAuthPort-oid NAME 'SecureEEClientAuthPort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( UnSecurePort-oid NAME 'UnSecurePort' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( SubsystemName-oid NAME 'SubsystemName' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( cmsUserGroup-oid NAME 'cmsUserGroup' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( realm-oid NAME 'realm' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( CertACLS-oid NAME 'CertACLS' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY resourceACLS X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( repository-oid NAME 'repository' DESC 'CMS defined class' SUP top STRUCTURAL MUST ou MAY ( serialno $ description $ nextRange $ publishingStatus ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( request-oid NAME 'request' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( requestId $ dateOfCreate $ dateOfModify $ requestState $ requestResult $ requestOwner $ requestAgentGroup $ requestSourceId $ requestType $ requestFlag $ requestError $ userMessages $ adminMessages $ realm ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( transaction-oid NAME 'transaction' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( transId $ description $ transName $ transStatus $ transOps ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( crlIssuingPointRecord-oid NAME 'crlIssuingPointRecord' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( dateOfCreate $ dateOfModify $ crlNumber $ crlSize $ thisUpdate $ nextUpdate $ deltaNumber $ deltaSize $ firstUnsaved $ certificateRevocationList $ deltaRevocationList $ crlCache $ revokedCerts $ unrevokedCerts $ expiredCerts $ cACertificate ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( certificateRecord-oid NAME 'certificateRecord' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( serialno $ dateOfCreate $ dateOfModify $ certStatus $ autoRenew $ issueInfo $ metaInfo $ revInfo $ version $ duration $ notAfter $ notBefore $ algorithmId $ subjectName $ signingAlgorithmId $ userCertificate $ issuedBy $ revokedBy $ revokedOn $ extension $ publicKeyData $ issuerName ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( userDetails-oid NAME 'userDetails' DESC 'CMS defined class' SUP top STRUCTURAL MUST userDN MAY ( dateOfCreate $ dateOfModify $ password $ p12Expiration ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( keyRecord-oid NAME 'keyRecord' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( serialno $ dateOfCreate $ dateOfModify $ keyState $ privateKeyData $ ownerName $ keySize $ metaInfo $ dateOfArchival $ dateOfRecovery $ algorithm $ publicKeyFormat $ publicKeyData $ archivedBy $ clientId $ dataType $ status $ realm ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( pkiSecurityDomain-oid NAME 'pkiSecurityDomain' DESC 'CMS defined class' SUP top STRUCTURAL MUST ( ou $ name ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( pkiSecurityGroup-oid NAME 'pkiSecurityGroup' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( pkiSubsystem-oid NAME 'pkiSubsystem' DESC 'CMS defined class' SUP top STRUCTURAL MUST ( cn $ Host $ SecurePort $ SubsystemName $ Clone ) MAY ( DomainManager $ SecureAgentPort $ SecureAdminPort $SecureEEClientAuthPort $ UnSecurePort ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( pkiRange-oid NAME 'pkiRange' DESC 'CMS defined class' SUP top STRUCTURAL MUST ( cn $ beginRange $ endRange $ Host $ SecurePort ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( securityDomainSessionEntry-oid NAME 'securityDomainSessionEntry' DESC 'CMS defined class' SUP top STRUCTURAL MUST ( cn $ host $ uid $ cmsUserGroup $ dateOfCreate ) X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfCreate-oid NAME 'dateOfCreate' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( dateOfModify-oid NAME 'dateOfModify' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( modified-oid NAME 'modified' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenUserID-oid NAME 'tokenUserID' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenStatus-oid NAME 'tokenStatus' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenAppletID-oid NAME 'tokenAppletID' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( keyInfo-oid NAME 'keyInfo' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( numberOfResets-oid NAME 'numberOfResets' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( numberOfEnrollments-oid NAME 'numberOfEnrollments' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( numberOfRenewals-oid NAME 'numberOfRenewals' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( numberOfRecoveries-oid NAME 'numberOfRecoveries' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( allowPinReset-oid NAME 'allowPinReset' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( extensions-oid NAME 'extensions' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenOp-oid NAME 'tokenOp' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenID-oid NAME 'tokenID' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenMsg-oid NAME 'tokenMsg' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenResult-oid NAME 'tokenResult' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenIP-oid NAME 'tokenIP' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenPolicy-oid NAME 'tokenPolicy' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenIssuer-oid NAME 'tokenIssuer' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenSubject-oid NAME 'tokenSubject' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenSerial-oid NAME 'tokenSerial' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenOrigin-oid NAME 'tokenOrigin' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenType-oid NAME 'tokenType' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenKeyType-oid NAME 'tokenKeyType' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenReason-oid NAME 'tokenReason' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenNotBefore-oid NAME 'tokenNotBefore' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( tokenNotAfter-oid NAME 'tokenNotAfter' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( profileID-oid NAME 'profileID' DESC 'CMS defined attribute' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( tokenRecord-oid NAME 'tokenRecord' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( dateOfCreate $ dateOfModify $ modified $ tokenReason $ tokenUserID $ tokenStatus $ tokenAppletID $ keyInfo $ tokenPolicy $ extensions $ numberOfResets $ numberOfEnrollments $ numberOfRenewals $ numberOfRecoveries $ userCertificate $ tokenType ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( tokenActivity-oid NAME 'tokenActivity' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( dateOfCreate $ dateOfModify $ tokenOp $ tokenIP $ tokenResult $ tokenID $ tokenUserID $ tokenMsg $ extensions $ tokenType ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( tokenCert-oid NAME 'tokenCert' DESC 'CMS defined class' SUP top STRUCTURAL MUST cn MAY ( dateOfCreate $ dateOfModify $ userCertificate $ tokenUserID $ tokenID $ tokenIssuer $ tokenOrigin $ tokenSubject $ tokenSerial $ tokenStatus $ tokenType $ tokenKeyType $ tokenNotBefore $ tokenNotAfter $ extensions ) X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( tpsProfileID-oid NAME 'tpsProfileID' DESC 'CMS defined class' SUP top AUXILIARY MAY ( profileID ) X-ORIGIN 'user-defined' ) INFO: Adding attributetypes: ( classId-oid NAME 'classId' DESC 'Certificate profile class ID' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( certProfileConfig-oid NAME 'certProfileConfig' DESC 'Certificate profile configuration' SYNTAX 1.3.6.1.4.1.1466.115.121.1.40 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( certProfile-oid NAME 'certProfile' DESC 'Certificate profile' SUP top STRUCTURAL MUST cn MAY ( classId $ certProfileConfig ) X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityID-oid NAME 'authorityID' DESC 'Authority ID' SYNTAX 1.3.6.1.4.1.1466.115.121.1.40 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityKeyNickname-oid NAME 'authorityKeyNickname' DESC 'Authority key nickname' SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE X-ORIGIN 'user-defined' ) INFO: Adding attributetypes: ( authorityParentID-oid NAME 'authorityParentID' DESC 'Authority Parent ID' SYNTAX 1.3.6.1.4.1.1466.115.121.1.40 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityEnabled-oid NAME 'authorityEnabled' DESC 'Authority Enabled' SYNTAX 1.3.6.1.4.1.1466.115.121.1.7 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityDN-oid NAME 'authorityDN' DESC 'Authority DN' SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authoritySerial-oid NAME 'authoritySerial' DESC 'Authority certificate serial number' SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityParentDN-oid NAME 'authorityParentDN' DESC 'Authority Parent DN' SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 SINGLE-VALUE X-ORIGIN 'user defined' ) INFO: Adding attributetypes: ( authorityKeyHost-oid NAME 'authorityKeyHost' DESC 'Authority Key Hosts' SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN 'user defined' ) INFO: Adding objectclasses: ( authority-oid NAME 'authority' DESC 'Certificate Authority' SUP top STRUCTURAL MUST ( cn $ authorityID $ authorityKeyNickname $ authorityEnabled $ authorityDN ) MAY ( authoritySerial $ authorityParentID $ authorityParentDN $ authorityKeyHost $ description ) X-ORIGIN 'user defined' ) INFO: Adding o=kra,o=ipaca INFO: Creating container entries INFO: Importing /usr/share/pki/kra/conf/db.ldif FINE: - database: ipaca FINE: - rootSuffix: o=kra,o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-14371135271577715434.ldif INFO: Adding ou=people,o=kra,o=ipaca INFO: Adding ou=groups,o=kra,o=ipaca INFO: Adding cn=Data Recovery Manager Agents,ou=groups,o=kra,o=ipaca INFO: Adding cn=Subsystem Group, ou=groups, o=kra,o=ipaca INFO: Adding cn=Trusted Managers,ou=groups,o=kra,o=ipaca INFO: Adding cn=Administrators,ou=groups,o=kra,o=ipaca INFO: Adding cn=Auditors,ou=groups,o=kra,o=ipaca INFO: Adding cn=ClonedSubsystems,ou=groups,o=kra,o=ipaca INFO: Adding cn=Security Domain Administrators,ou=groups,o=kra,o=ipaca INFO: Adding cn=Enterprise KRA Administrators,ou=groups,o=kra,o=ipaca INFO: Adding ou=requests,o=kra,o=ipaca INFO: Adding cn=crossCerts,o=kra,o=ipaca INFO: Adding ou=kra, o=kra,o=ipaca INFO: Adding ou=keyRepository, ou=kra, o=kra,o=ipaca INFO: Adding ou=kra, ou=requests, o=kra,o=ipaca INFO: Adding ou=replica,o=kra,o=ipaca INFO: Adding ou=ranges,o=kra,o=ipaca INFO: Adding ou=replica, ou=ranges,o=kra,o=ipaca INFO: Adding ou=requests, ou=ranges,o=kra,o=ipaca INFO: Adding ou=keyRepository, ou=ranges,o=kra,o=ipaca INFO: Setting up ACL INFO: Importing /usr/share/pki/kra/conf/acl.ldif FINE: - database: ipaca FINE: - rootSuffix: o=kra,o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-1984311471323307919.ldif INFO: Adding cn=aclResources,o=kra,o=ipaca INFO: Creating indexes INFO: Importing /usr/share/pki/kra/conf/index.ldif FINE: - database: ipaca FINE: - rootSuffix: o=kra,o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-6506085189637850426.ldif INFO: Adding cn=revokedby,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=revokedby,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=issuedby,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=issuedby,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=publicKeyData,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=publicKeyData,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=clientId,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=clientId,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=dataType,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=dataType,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=status,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=status,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=description,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=description,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=serialno,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=serialno,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=metaInfo,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=metaInfo,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=certstatus,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=certstatus,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=requestid,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=requestid,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=requesttype,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=requesttype,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=requeststate,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=requeststate,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=requestowner,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=requestowner,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=notbefore,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=notbefore,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=notafter,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=notafter,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=duration,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=duration,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=dateOfCreate,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=dateOfCreate,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=revokedOn,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=revokedOn,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=archivedBy,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=archivedBy,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=ownername,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=ownername,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=subjectname,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=subjectname,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=requestsourceid,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=requestsourceid,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=revInfo,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=revInfo,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=extension,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config INFO: Unable to add cn=extension,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config: netscape.ldap.LDAPException: Already exists (68) INFO: Adding cn=realm,cn=index,cn=ipaca,cn=ldbm database, cn=plugins, cn=config FINE: PKIClientSocketListener.alertReceived: begins FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert received: FINE: - reason: clientAlertReceived: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: PKIClientSocketListener.alertSent: begins FINE: PKIClientSocketListener.alertSent: got description:0 FINE: PKIClientSocketListener.alertSent: got reason:clientAlertSent: CLOSE_NOTIFY FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert sent: FINE: - reason: clientAlertSent: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - subject: SYSTEM FINE: - server port: 636 DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/kra/webapps/kra/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI kra-db-access-grant --debug uid=pkidbuser,ou=people,o=ipaca FINE: SubsystemDBAccessGrantCLI: Loading /var/lib/pki/pki-tomcat/kra/conf/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:636 with basic auth as cn=Directory Manager FINE: ldapconn/PKISocketFactory.makeSSLSocket: begins FINE: PKIClientSocketListener.handshakeCompleted: begins FINE: PKIClientSocketListener: Handshake completed: FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_ESTABLISH FINE: SSL handshake happened INFO: Granting database access to uid=pkidbuser,ou=people,o=ipaca INFO: Importing /usr/share/pki/server/conf/db-access-grant.ldif FINE: - dbuser: uid=pkidbuser,ou=people,o=ipaca FINE: - database: ipaca FINE: - rootSuffix: o=kra,o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-15840846279583122143.ldif INFO: Adding aci into o=kra,o=ipaca INFO: Adding aci into cn=ldbm database,cn=plugins,cn=config INFO: Unable to modify cn=ldbm database,cn=plugins,cn=config: netscape.ldap.LDAPException: Type or value exists (20) INFO: Adding aci into cn=config INFO: Unable to modify cn=config: netscape.ldap.LDAPException: Type or value exists (20) INFO: Adding aci into ou=csusers,cn=config INFO: Unable to modify ou=csusers,cn=config: netscape.ldap.LDAPException: Type or value exists (20) INFO: Adding aci into cn="o=kra,o=ipaca",cn=mapping tree,cn=config INFO: Unable to modify cn="o=kra,o=ipaca",cn=mapping tree,cn=config: netscape.ldap.LDAPException: No such object (32) INFO: Adding aci into cn="o=kra,o=ipaca",cn=mapping tree,cn=config INFO: Unable to modify cn="o=kra,o=ipaca",cn=mapping tree,cn=config: netscape.ldap.LDAPException: No such object (32) INFO: Adding aci into cn="o=kra,o=ipaca",cn=mapping tree,cn=config INFO: Unable to modify cn="o=kra,o=ipaca",cn=mapping tree,cn=config: netscape.ldap.LDAPException: No such object (32) INFO: Adding aci into cn=tasks,cn=config INFO: Unable to modify cn=tasks,cn=config: netscape.ldap.LDAPException: Type or value exists (20) FINE: PKIClientSocketListener.alertReceived: begins FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert received: FINE: - reason: clientAlertReceived: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: PKIClientSocketListener.alertSent: begins FINE: PKIClientSocketListener.alertSent: got description:0 FINE: PKIClientSocketListener.alertSent: got reason:clientAlertSent: CLOSE_NOTIFY FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert sent: FINE: - reason: clientAlertSent: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - subject: SYSTEM FINE: - server port: 636 DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/kra/webapps/kra/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI kra-db-vlv-add --debug FINE: SubsystemDBVLVAddCLI: Loading /var/lib/pki/pki-tomcat/kra/conf/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:636 with basic auth as cn=Directory Manager FINE: ldapconn/PKISocketFactory.makeSSLSocket: begins FINE: PKIClientSocketListener.handshakeCompleted: begins FINE: PKIClientSocketListener: Handshake completed: FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_ESTABLISH FINE: SSL handshake happened INFO: Add VLVs INFO: Importing /usr/share/pki/kra/conf/vlv.ldif FINE: - database: ipaca FINE: - instanceId: pki-tomcat FINE: - rootSuffix: o=kra,o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-8418679455953629618.ldif INFO: Adding cn=allKeys-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraAll-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraArchival-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraRecovery-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraCanceled-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraCanceledEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraCanceledRecovery-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraRejected-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraRejectedEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraRejectedRecovery-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraComplete-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraCompleteEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraCompleteRecovery-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=allKeys-pki-tomcatIndex, cn=allKeys-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraAll-pki-tomcatIndex, cn=kraAll-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraArchival-pki-tomcatIndex, cn=kraArchival-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraRecovery-pki-tomcatIndex, cn=kraRecovery-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraCanceled-pki-tomcatIndex, cn=kraCanceled-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraCanceledEnrollment-pki-tomcatIndex, cn=kraCanceledEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraCanceledRecovery-pki-tomcatIndex, cn=kraCanceledRecovery-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraRejected-pki-tomcatIndex, cn=kraRejected-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraRejectedEnrollment-pki-tomcatIndex, cn=kraRejectedEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraRejectedRecovery-pki-tomcatIndex, cn=kraRejectedRecovery-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraComplete-pki-tomcatIndex, cn=kraComplete-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraCompleteEnrollment-pki-tomcatIndex, cn=kraCompleteEnrollment-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config INFO: Adding cn=kraCompleteRecovery-pki-tomcatIndex, cn=kraCompleteRecovery-pki-tomcat, cn=ipaca, cn=ldbm database, cn=plugins, cn=config FINE: PKIClientSocketListener.alertReceived: begins FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert received: FINE: - reason: clientAlertReceived: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: PKIClientSocketListener.alertSent: begins FINE: PKIClientSocketListener.alertSent: got description:0 FINE: PKIClientSocketListener.alertSent: got reason:clientAlertSent: CLOSE_NOTIFY FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert sent: FINE: - reason: clientAlertSent: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - subject: SYSTEM FINE: - server port: 636 DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/kra/webapps/kra/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI kra-db-vlv-reindex --debug FINE: SubsystemDBVLVReindexCLI: Loading /var/lib/pki/pki-tomcat/kra/conf/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:636 with basic auth as cn=Directory Manager FINE: ldapconn/PKISocketFactory.makeSSLSocket: begins FINE: PKIClientSocketListener.handshakeCompleted: begins FINE: PKIClientSocketListener: Handshake completed: FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_ESTABLISH FINE: SSL handshake happened INFO: Reindex VLVs INFO: Importing /usr/share/pki/kra/conf/vlvtasks.ldif FINE: - database: ipaca FINE: - instanceId: pki-tomcat FINE: - rootSuffix: o=kra,o=ipaca INFO: Creating /var/lib/pki/pki-tomcat/temp/pki-import-1236070031451676865.ldif INFO: Adding cn=index1160527115, cn=index, cn=tasks, cn=config INFO: Waiting for task cn=index1160527115, cn=index, cn=tasks, cn=config (1s) INFO: Getting cn=index1160527115, cn=index, cn=tasks, cn=config INFO: Task cn=index1160527115, cn=index, cn=tasks, cn=config complete FINE: PKIClientSocketListener.alertReceived: begins FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert received: FINE: - reason: clientAlertReceived: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: PKIClientSocketListener.alertSent: begins FINE: PKIClientSocketListener.alertSent: got description:0 FINE: PKIClientSocketListener.alertSent: got reason:clientAlertSent: CLOSE_NOTIFY FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert sent: FINE: - reason: clientAlertSent: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - subject: SYSTEM FINE: - server port: 636 INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/kra/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/kra/conf/registry.cfg INFO: Enabling KRA subsystem INFO: Creating /etc/pki/pki-tomcat/Catalina/localhost/kra.xml INFO: Waiting for web application to start INFO: Web application started INFO: Waiting for KRA subsystem INFO: Subsystem status: running DEBUG: PKIDeployer.setup_system_certs() INFO: Setting up transport cert DEBUG: PKISubsystem.get_subsystem_cert(transport) INFO: Getting transport cert info from CS.cfg DEBUG: PKISubsystem.get_nssdb_cert_info(transport) INFO: Getting transport cert info from NSS database DEBUG: NSSDatabase.get_cert_info(transportCert cert-pki-kra) begins DEBUG: NSSDatabase.get_cert(transportCert cert-pki-kra) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmppnlzv060/password.txt -n transportCert cert-pki-kra -a DEBUG: Cert not found: transportCert cert-pki-kra DEBUG: PKIDeployer.setup_system_cert() DEBUG: NSSDatabase.get_cert_info(transportCert cert-pki-kra) begins DEBUG: NSSDatabase.get_cert(transportCert cert-pki-kra) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmpavxq8co1/password.txt -n transportCert cert-pki-kra -a DEBUG: Cert not found: transportCert cert-pki-kra INFO: transport cert does not exist in NSS database INFO: Creating transport key DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmpcz1wn9jh/password.txt nss-key-create --output-format json --key-type RSA --key-size 2048 --key-wrap --debug INFO: - key ID: 0x8a8d3d16bdf8f34e2ab8ce1e3e56e83e4ba655e1 INFO: Creating transport cert request DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmp9ewy0wp_/password.txt nss-cert-request --subject cn=KRA Transport Certificate,O=REDACTED_DOMAIN.COM --csr /tmp/tmpa21lr669/request.csr --key-id 0x8a8d3d16bdf8f34e2ab8ce1e3e56e83e4ba655e1 --hash SHA256 --debug INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Loading key 0x8a8d3d16bdf8f34e2ab8ce1e3e56e83e4ba655e1 FINE: NSSDatabase: - class: org.mozilla.jss.pkcs11.PK11RSAPrivateKey FINE: NSSDatabase: - algorithm: RSA FINE: NSSDatabase: - format: null FINE: NSSDatabase: - key type: RSA FINE: NSSDatabase: - size: 2048 FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: cn=KRA Transport Certificate,O=REDACTED_DOMAIN.COM FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: cn=KRA Transport Certificate,O=REDACTED_DOMAIN.COM FINE: CryptoUtil: - attributes: DEBUG: - request: MIICgzCCAWsCAQAwPjEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMSIwIAYDVQQDDBlLUkEgVHJhbnNwb3J0IENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAstjzvgh9FpOoR2y6MCstHbc2T219Thx7MYWlzMSww9d2DxMka4yHGszKqnOpF7ihAxBU0zZC7GLRmWkmtFQ7Cn9M6SFkr9xhHnAS7H2QDstTb9wEMkC7gpZk6yHKwfzWB03z84nQodsko2QMwcxDUW3m3v8jJH0R0KG5VtxViklPa5eOFlGcRnnrfmCKkNU+wndSIXxJdcp/77l3YjUIS/dUdAk3VgEIJEzFNFplAiyshzQsAE/AQo57Q30u5ZKxQ2CBlw3E2wRSzw0FL7ea5xhHKtDvoPeoob2B0Ym37Klfwvd8MVKvrGDLoq7qJtYn7FQIkz+SwPlUVLaT13+7AwIDAQABoAAwDQYJKoZIhvcNAQELBQADggEBAFy9O7xfm5KgkM+mHDA+/a9/qcSO5mjHd9YgaGIbq6Pcx28v+Cvac1UaUmutzq1YCMMFS7zgN27YQM9KSM8C7skwVUUKzMLyj6bMc+AAipy/n4w7YpwZpCURCpTwllWYwoW2D8U56qz5zzJEGj3oaMG/onfehCk+HtEqsIaPLV+SmNJ49i7Fcp+m4jW+5yhR7MRX0jxO3Ajr/szcMSiieEQybxZhZ2a5Cl0kINyqkAZ2iJJkQMkL7Wa1OEFjdQX0TqddrgpAIJePSPKex18WCNlcLGzhtHqYB5RSlhM63xzLGmA3mwu+4fLnor0MPGZkerBtLHMSrkr3q5R7T1UczBo= INFO: Requesting transport cert from https://master.redacted_domain.com:443 DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -f /etc/pki/pki-tomcat/password.conf -U https://master.redacted_domain.com:443 --ignore-banner ca-cert-request-submit --request-type pkcs10 --csr-file /tmp/tmpijl6q91x/request.csr --profile caInternalAuthTransportCert --subject cn=KRA Transport Certificate,O=REDACTED_DOMAIN.COM --requestor KRA-master.redacted_domain.com-8443 --install-token /tmp/tmpijl6q91x/install-token --output-format PEM --debug INFO: Retrieving caInternalAuthTransportCert profile INFO: Connecting to https://master.redacted_domain.com:443 INFO: HTTP request: GET /pki/rest/info HTTP/1.1 INFO: Accept: application/json INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: INFO: Server certificate: CN=master.redacted_domain.com,O=REDACTED_DOMAIN.COM INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:14 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Set-Cookie: JSESSIONID=80F2BA86F0DBAD244C7CAD619C7D836B; Path=/pki; Secure; HttpOnly INFO: Content-Type: application/json INFO: Content-Length: 50 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=100 INFO: Connection: Keep-Alive FINE: Response: {"Version":"11.2.0","Attributes":{"Attribute":[]}} INFO: Server Name: null INFO: Server Version: 11.2.0 INFO: HTTP request: GET /ca/rest/certrequests/profiles/caInternalAuthTransportCert HTTP/1.1 INFO: Accept: application/json INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:14 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Content-Type: application/json INFO: Content-Length: 912 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=99 INFO: Connection: Keep-Alive FINE: Response: {"ProfileID":"caInternalAuthTransportCert","Renewal":false,"RemoteHost":"","RemoteAddress":"","Input":[{"id":"i1","ClassID":"certReqInputImpl","Name":"Certificate Request Input","ConfigAttribute":[],"Attribute":[{"name":"cert_request_type","Value":"","Descriptor":{"Syntax":"cert_request_type","Description":"Certificate Request Type"}},{"name":"cert_request","Value":"","Descriptor":{"Syntax":"cert_request","Description":"Certificate Request"}}]},{"id":"i2","ClassID":"submitterInfoInputImpl","Name":"Requestor Information","ConfigAttribute":[],"Attribute":[{"name":"requestor_name","Value":"","Descriptor":{"Syntax":"string","Description":"Requestor Name"}},{"name":"requestor_email","Value":"","Descriptor":{"Syntax":"string","Description":"Requestor Email"}},{"name":"requestor_phone","Value":"","Descriptor":{"Syntax":"string","Description":"Requestor Phone"}}]}],"Output":[],"Attributes":{"Attribute":[]}} INFO: Request type: pkcs10 INFO: CSR: -----BEGIN CERTIFICATE REQUEST----- MIICgzCCAWsCAQAwPjEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMSIwIAYDVQQD DBlLUkEgVHJhbnNwb3J0IENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOC AQ8AMIIBCgKCAQEAstjzvgh9FpOoR2y6MCstHbc2T219Thx7MYWlzMSww9d2DxMk a4yHGszKqnOpF7ihAxBU0zZC7GLRmWkmtFQ7Cn9M6SFkr9xhHnAS7H2QDstTb9wE MkC7gpZk6yHKwfzWB03z84nQodsko2QMwcxDUW3m3v8jJH0R0KG5VtxViklPa5eO FlGcRnnrfmCKkNU+wndSIXxJdcp/77l3YjUIS/dUdAk3VgEIJEzFNFplAiyshzQs AE/AQo57Q30u5ZKxQ2CBlw3E2wRSzw0FL7ea5xhHKtDvoPeoob2B0Ym37Klfwvd8 MVKvrGDLoq7qJtYn7FQIkz+SwPlUVLaT13+7AwIDAQABoAAwDQYJKoZIhvcNAQEL BQADggEBAFy9O7xfm5KgkM+mHDA+/a9/qcSO5mjHd9YgaGIbq6Pcx28v+Cvac1Ua Umutzq1YCMMFS7zgN27YQM9KSM8C7skwVUUKzMLyj6bMc+AAipy/n4w7YpwZpCUR CpTwllWYwoW2D8U56qz5zzJEGj3oaMG/onfehCk+HtEqsIaPLV+SmNJ49i7Fcp+m 4jW+5yhR7MRX0jxO3Ajr/szcMSiieEQybxZhZ2a5Cl0kINyqkAZ2iJJkQMkL7Wa1 OEFjdQX0TqddrgpAIJePSPKex18WCNlcLGzhtHqYB5RSlhM63xzLGmA3mwu+4fLn or0MPGZkerBtLHMSrkr3q5R7T1UczBo= -----END CERTIFICATE REQUEST----- INFO: Request: com.netscape.certsrv.cert.CertEnrollmentRequest@cebf3b92 INFO: DNS names: null INFO: Requestor: KRA-master.redacted_domain.com-8443 INFO: HTTP request: POST /ca/ee/ca/profileSubmit HTTP/1.1 INFO: Content-Type: application/x-www-form-urlencoded INFO: Content-Length: 1252 INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: xmlOutput=true&cert_request_type=pkcs10&profileId=caInternalAuthTransportCert&cert_request=-----BEGIN+CERTIFICATE+REQUEST-----%0AMIICgzCCAWsCAQAwPjEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMSIwIAYDVQQD%0ADBlLUkEgVHJhbnNwb3J0IENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOC%0AAQ8AMIIBCgKCAQEAstjzvgh9FpOoR2y6MCstHbc2T219Thx7MYWlzMSww9d2DxMk%0Aa4yHGszKqnOpF7ihAxBU0zZC7GLRmWkmtFQ7Cn9M6SFkr9xhHnAS7H2QDstTb9wE%0AMkC7gpZk6yHKwfzWB03z84nQodsko2QMwcxDUW3m3v8jJH0R0KG5VtxViklPa5eO%0AFlGcRnnrfmCKkNU%2BwndSIXxJdcp%2F77l3YjUIS%2FdUdAk3VgEIJEzFNFplAiyshzQs%0AAE%2FAQo57Q30u5ZKxQ2CBlw3E2wRSzw0FL7ea5xhHKtDvoPeoob2B0Ym37Klfwvd8%0AMVKvrGDLoq7qJtYn7FQIkz%2BSwPlUVLaT13%2B7AwIDAQABoAAwDQYJKoZIhvcNAQEL%0ABQADggEBAFy9O7xfm5KgkM%2BmHDA%2B%2Fa9%2FqcSO5mjHd9YgaGIbq6Pcx28v%2BCvac1Ua%0AUmutzq1YCMMFS7zgN27YQM9KSM8C7skwVUUKzMLyj6bMc%2BAAipy%2Fn4w7YpwZpCUR%0ACpTwllWYwoW2D8U56qz5zzJEGj3oaMG%2FonfehCk%2BHtEqsIaPLV%2BSmNJ49i7Fcp%2Bm%0A4jW%2B5yhR7MRX0jxO3Ajr%2FszcMSiieEQybxZhZ2a5Cl0kINyqkAZ2iJJkQMkL7Wa1%0AOEFjdQX0TqddrgpAIJePSPKex18WCNlcLGzhtHqYB5RSlhM63xzLGmA3mwu%2B4fLn%0Aor0MPGZkerBtLHMSrkr3q5R7T1UczBo%3D%0A-----END+CERTIFICATE+REQUEST-----%0A&subject=cn%3DKRA+Transport+Certificate%2CO%3DREDACTED_DOMAIN.COM&requestor_name=KRA-master.redacted_domain.com-8443&sessionID=657561939077568930 INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:14 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Content-Type: application/xml INFO: Content-Length: 1624 INFO: Keep-Alive: timeout=30, max=98 INFO: Connection: Keep-Alive FINE: Response: 011CN=KRA Transport Certificate,O=REDACTED_DOMAIN.COMbMIIEADCCAmigAwIBAgIBCzANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MTRaFw0yNDEyMDYyMzU3MTRaMD4xGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEiMCAGA1UEAwwZS1JBIFRyYW5zcG9ydCBDZXJ0aWZpY2F0ZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALLY874IfRaTqEdsujArLR23Nk9tfU4cezGFpczEsMPXdg8TJGuMhxrMyqpzqRe4oQMQVNM2Quxi0ZlpJrRUOwp/TOkhZK/cYR5wEux9kA7LU2/cBDJAu4KWZOshysH81gdN8/OJ0KHbJKNkDMHMQ1Ft5t7/IyR9EdChuVbcVYpJT2uXjhZRnEZ5635gipDVPsJ3UiF8SXXKf++5d2I1CEv3VHQJN1YBCCRMxTRaZQIsrIc0LABPwEKOe0N9LuWSsUNggZcNxNsEUs8NBS+3mucYRyrQ76D3qKG9gdGJt+ypX8L3fDFSr6xgy6Ku6ibWJ+xUCJM/ksD5VFS2k9d/uwMCAwEAAaOBjDCBiTAfBgNVHSMEGDAWgBScIczpp3CvTwb9lf5YX37B9mehxjBBBggrBgEFBQcBAQQ1MDMwMQYIKwYBBQUHMAGGJWh0dHA6Ly9pcGEtY2EubW9uaXZhZ3JvdXAuY29tL2NhL29jc3AwDgYDVR0PAQH/BAQDAgTwMBMGA1UdJQQMMAoGCCsGAQUFBwMCMA0GCSqGSIb3DQEBDQUAA4IBgQBC+olBeGrdYxTMQGsxRVmYSxiM2RuT09L0eTL3nxn6S/UZhKGH7NeoipaTPHezq/cxZAT0INLfpt6iWMjRgCS8jCCQpckyjB/C7qU3JPx8aAm+OevYwe6Zgy7CqiNxPdn9r/BE6IVHCVjhUC8TFsICkLFL5Y4v1q+ZeocAcO6w+vrfeS14ajRDH6/1nE1unTfaXgFG6tdgc2Cmye8mWOZVgRytb6KZdYFC93x7ab0OlHry07ip0IjLAn941+vpIXy8CHXE74/3R9huLL51s0mB2JAq/uBk3724Q4rB58I/PRrl2EHnZQRb8zMZsTjqFtQWtDNPoVvD/UDIgyqJ/A+QKAx9sK+XWEwNZdw+t54JpkEduXtFwXNp5yxHSuaQOqf1IfG5svbmW9V25Dr0J2AgaIU4z8xgJwk7QM77TU63tzfjwBYvhrLolXSf1OMXBD8feIZsr91h8HvQccARSZmAo96tnSbC6finiQ3tUzO7bmb8Fzk3yyfr13aqb2yQybc= FINE: CACertClient: Response: 011CN=KRA Transport Certificate,O=REDACTED_DOMAIN.COMbMIIEADCCAmigAwIBAgIBCzANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MTRaFw0yNDEyMDYyMzU3MTRaMD4xGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEiMCAGA1UEAwwZS1JBIFRyYW5zcG9ydCBDZXJ0aWZpY2F0ZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALLY874IfRaTqEdsujArLR23Nk9tfU4cezGFpczEsMPXdg8TJGuMhxrMyqpzqRe4oQMQVNM2Quxi0ZlpJrRUOwp/TOkhZK/cYR5wEux9kA7LU2/cBDJAu4KWZOshysH81gdN8/OJ0KHbJKNkDMHMQ1Ft5t7/IyR9EdChuVbcVYpJT2uXjhZRnEZ5635gipDVPsJ3UiF8SXXKf++5d2I1CEv3VHQJN1YBCCRMxTRaZQIsrIc0LABPwEKOe0N9LuWSsUNggZcNxNsEUs8NBS+3mucYRyrQ76D3qKG9gdGJt+ypX8L3fDFSr6xgy6Ku6ibWJ+xUCJM/ksD5VFS2k9d/uwMCAwEAAaOBjDCBiTAfBgNVHSMEGDAWgBScIczpp3CvTwb9lf5YX37B9mehxjBBBggrBgEFBQcBAQQ1MDMwMQYIKwYBBQUHMAGGJWh0dHA6Ly9pcGEtY2EubW9uaXZhZ3JvdXAuY29tL2NhL29jc3AwDgYDVR0PAQH/BAQDAgTwMBMGA1UdJQQMMAoGCCsGAQUFBwMCMA0GCSqGSIb3DQEBDQUAA4IBgQBC+olBeGrdYxTMQGsxRVmYSxiM2RuT09L0eTL3nxn6S/UZhKGH7NeoipaTPHezq/cxZAT0INLfpt6iWMjRgCS8jCCQpckyjB/C7qU3JPx8aAm+OevYwe6Zgy7CqiNxPdn9r/BE6IVHCVjhUC8TFsICkLFL5Y4v1q+ZeocAcO6w+vrfeS14ajRDH6/1nE1unTfaXgFG6tdgc2Cmye8mWOZVgRytb6KZdYFC93x7ab0OlHry07ip0IjLAn941+vpIXy8CHXE74/3R9huLL51s0mB2JAq/uBk3724Q4rB58I/PRrl2EHnZQRb8zMZsTjqFtQWtDNPoVvD/UDIgyqJ/A+QKAx9sK+XWEwNZdw+t54JpkEduXtFwXNp5yxHSuaQOqf1IfG5svbmW9V25Dr0J2AgaIU4z8xgJwk7QM77TU63tzfjwBYvhrLolXSf1OMXBD8feIZsr91h8HvQccARSZmAo96tnSbC6finiQ3tUzO7bmb8Fzk3yyfr13aqb2yQybc= FINE: CACertClient: - status: 0 FINE: CACertClient: - request ID: 0xb FINE: CACertClient: - serial: b FINE: CACertClient: - cert: MIIEADCCAmigAwIBAgIBCzANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MTRaFw0yNDEyMDYyMzU3MTRaMD4xGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEiMCAGA1UEAwwZS1JBIFRyYW5zcG9ydCBDZXJ0aWZpY2F0ZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALLY874IfRaTqEdsujArLR23Nk9tfU4cezGFpczEsMPXdg8TJGuMhxrMyqpzqRe4oQMQVNM2Quxi0ZlpJrRUOwp/TOkhZK/cYR5wEux9kA7LU2/cBDJAu4KWZOshysH81gdN8/OJ0KHbJKNkDMHMQ1Ft5t7/IyR9EdChuVbcVYpJT2uXjhZRnEZ5635gipDVPsJ3UiF8SXXKf++5d2I1CEv3VHQJN1YBCCRMxTRaZQIsrIc0LABPwEKOe0N9LuWSsUNggZcNxNsEUs8NBS+3mucYRyrQ76D3qKG9gdGJt+ypX8L3fDFSr6xgy6Ku6ibWJ+xUCJM/ksD5VFS2k9d/uwMCAwEAAaOBjDCBiTAfBgNVHSMEGDAWgBScIczpp3CvTwb9lf5YX37B9mehxjBBBggrBgEFBQcBAQQ1MDMwMQYIKwYBBQUHMAGGJWh0dHA6Ly9pcGEtY2EubW9uaXZhZ3JvdXAuY29tL2NhL29jc3AwDgYDVR0PAQH/BAQDAgTwMBMGA1UdJQQMMAoGCCsGAQUFBwMCMA0GCSqGSIb3DQEBDQUAA4IBgQBC+olBeGrdYxTMQGsxRVmYSxiM2RuT09L0eTL3nxn6S/UZhKGH7NeoipaTPHezq/cxZAT0INLfpt6iWMjRgCS8jCCQpckyjB/C7qU3JPx8aAm+OevYwe6Zgy7CqiNxPdn9r/BE6IVHCVjhUC8TFsICkLFL5Y4v1q+ZeocAcO6w+vrfeS14ajRDH6/1nE1unTfaXgFG6tdgc2Cmye8mWOZVgRytb6KZdYFC93x7ab0OlHry07ip0IjLAn941+vpIXy8CHXE74/3R9huLL51s0mB2JAq/uBk3724Q4rB58I/PRrl2EHnZQRb8zMZsTjqFtQWtDNPoVvD/UDIgyqJ/A+QKAx9sK+XWEwNZdw+t54JpkEduXtFwXNp5yxHSuaQOqf1IfG5svbmW9V25Dr0J2AgaIU4z8xgJwk7QM77TU63tzfjwBYvhrLolXSf1OMXBD8feIZsr91h8HvQccARSZmAo96tnSbC6finiQ3tUzO7bmb8Fzk3yyfr13aqb2yQybc= INFO: - serial: 0xb INFO: Storing cert and request for transport INFO: Importing transport cert into NSS database DEBUG: NSSDatabase.add_cert(transportCert cert-pki-kra) DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmp9ewy0wp_/password.txt nss-cert-import --format PEM --debug transportCert cert-pki-kra INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Storing password into /tmp/nss-password-17378935161195688313.txt FINE: NSSDatabase: Command: certutil -A -d /etc/pki/pki-tomcat/alias -f /tmp/nss-password-17378935161195688313.txt -a -n "transportCert cert-pki-kra" -t ,, -i /tmp/nss-cert-5037442296629381506.crt INFO: Setting up storage cert DEBUG: PKISubsystem.get_subsystem_cert(storage) INFO: Getting storage cert info from CS.cfg DEBUG: PKISubsystem.get_nssdb_cert_info(storage) INFO: Getting storage cert info from NSS database DEBUG: NSSDatabase.get_cert_info(storageCert cert-pki-kra) begins DEBUG: NSSDatabase.get_cert(storageCert cert-pki-kra) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmp8uf1u_de/password.txt -n storageCert cert-pki-kra -a DEBUG: Cert not found: storageCert cert-pki-kra DEBUG: PKIDeployer.setup_system_cert() DEBUG: NSSDatabase.get_cert_info(storageCert cert-pki-kra) begins DEBUG: NSSDatabase.get_cert(storageCert cert-pki-kra) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmpofq35s1l/password.txt -n storageCert cert-pki-kra -a DEBUG: Cert not found: storageCert cert-pki-kra INFO: storage cert does not exist in NSS database INFO: Creating storage key DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmp45rvo82b/password.txt nss-key-create --output-format json --key-type RSA --key-size 2048 --key-wrap --debug INFO: - key ID: 0xfcc350db3471f4789562a0fb466c6541740a888e INFO: Creating storage cert request DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmp9ewy0wp_/password.txt nss-cert-request --subject cn=KRA Storage Certificate,O=REDACTED_DOMAIN.COM --csr /tmp/tmpmtepaeac/request.csr --key-id 0xfcc350db3471f4789562a0fb466c6541740a888e --hash SHA256 --debug INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Loading key 0xfcc350db3471f4789562a0fb466c6541740a888e FINE: NSSDatabase: - class: org.mozilla.jss.pkcs11.PK11RSAPrivateKey FINE: NSSDatabase: - algorithm: RSA FINE: NSSDatabase: - format: null FINE: NSSDatabase: - key type: RSA FINE: NSSDatabase: - size: 2048 FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: cn=KRA Storage Certificate,O=REDACTED_DOMAIN.COM FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: cn=KRA Storage Certificate,O=REDACTED_DOMAIN.COM FINE: CryptoUtil: - attributes: DEBUG: - request: MIICgTCCAWkCAQAwPDEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMSAwHgYDVQQDDBdLUkEgU3RvcmFnZSBDZXJ0aWZpY2F0ZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALvNjszq6QvI5RGs4wahPpjwtUyzv8ErCjLeWXnpLX7zgXhCoWI6fZj2iCyfRdt/gOXQFuRi7Z0y0JLF0BFE9NXzjCn3+hfZRRNSlvKTDARP6SsSB9Qh2G4DF0aoyLkQkPx5DeECMQ8u2xqin8t8IYcXz3BgeIGr0hm51DfankUYfK1XrCWRm2Rbhjr01DUjrQKIvacC5vvN/a2RrkRH4PTOK0e6lFqrAv0Ds23jW46L5XgCTL9svtQqvJqmBqwetgsqgV3+s0t7UAFqHYQoQHHEO1dYsLf1otFeddq0Bj0J4jDrjDmgWuxJNZ6cbNcRJn3aOgF74pE8qGwb8adW8IECAwEAAaAAMA0GCSqGSIb3DQEBCwUAA4IBAQBtKJAZWhbNJMR0wDKEnnPK/2nsrPrfGVu9fO77Daew1FGhn4lw78GAequvYg5zWOXx5aKlhFuYpzZLs5Jb1XqD8dk1it0iTi6xHGXXZB3RflchBJLElJMpEecQ5Iicc9uc2nEQU2UorG64isXFh73W/dBkPXrx2EvX5Smo3de/fiMi546OGeMj025lf+JhuwuyAAOgOr0wqVavTA+2feOj3kyLOpVwAHTDkN+vyiWjIJtVuc8ORofZ8M5nLFm3qx47kOUlitF8fltd30ikzHSTXYiKSxBdDWbZ5SEAh9KPeJPk23j+iexddPyMTuczHYEKPFpTLR6Xzm/sAdhdppa2 INFO: Requesting storage cert from https://master.redacted_domain.com:443 DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -f /etc/pki/pki-tomcat/password.conf -U https://master.redacted_domain.com:443 --ignore-banner ca-cert-request-submit --request-type pkcs10 --csr-file /tmp/tmpe33vp9bp/request.csr --profile caInternalAuthDRMstorageCert --subject cn=KRA Storage Certificate,O=REDACTED_DOMAIN.COM --requestor KRA-master.redacted_domain.com-8443 --install-token /tmp/tmpe33vp9bp/install-token --output-format PEM --debug INFO: Retrieving caInternalAuthDRMstorageCert profile INFO: Connecting to https://master.redacted_domain.com:443 INFO: HTTP request: GET /pki/rest/info HTTP/1.1 INFO: Accept: application/json INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: INFO: Server certificate: CN=master.redacted_domain.com,O=REDACTED_DOMAIN.COM INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:21 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Set-Cookie: JSESSIONID=2BA304F24FD77D42120CD7A168F1FFD3; Path=/pki; Secure; HttpOnly INFO: Content-Type: application/json INFO: Content-Length: 50 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=100 INFO: Connection: Keep-Alive FINE: Response: {"Version":"11.2.0","Attributes":{"Attribute":[]}} INFO: Server Name: null INFO: Server Version: 11.2.0 INFO: HTTP request: GET /ca/rest/certrequests/profiles/caInternalAuthDRMstorageCert HTTP/1.1 INFO: Accept: application/json INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:21 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Content-Type: application/json INFO: Content-Length: 913 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=99 INFO: Connection: Keep-Alive FINE: Response: {"ProfileID":"caInternalAuthDRMstorageCert","Renewal":false,"RemoteHost":"","RemoteAddress":"","Input":[{"id":"i1","ClassID":"certReqInputImpl","Name":"Certificate Request Input","ConfigAttribute":[],"Attribute":[{"name":"cert_request_type","Value":"","Descriptor":{"Syntax":"cert_request_type","Description":"Certificate Request Type"}},{"name":"cert_request","Value":"","Descriptor":{"Syntax":"cert_request","Description":"Certificate Request"}}]},{"id":"i2","ClassID":"submitterInfoInputImpl","Name":"Requestor Information","ConfigAttribute":[],"Attribute":[{"name":"requestor_name","Value":"","Descriptor":{"Syntax":"string","Description":"Requestor Name"}},{"name":"requestor_email","Value":"","Descriptor":{"Syntax":"string","Description":"Requestor Email"}},{"name":"requestor_phone","Value":"","Descriptor":{"Syntax":"string","Description":"Requestor Phone"}}]}],"Output":[],"Attributes":{"Attribute":[]}} INFO: Request type: pkcs10 INFO: CSR: -----BEGIN CERTIFICATE REQUEST----- MIICgTCCAWkCAQAwPDEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMSAwHgYDVQQD DBdLUkEgU3RvcmFnZSBDZXJ0aWZpY2F0ZTCCASIwDQYJKoZIhvcNAQEBBQADggEP ADCCAQoCggEBALvNjszq6QvI5RGs4wahPpjwtUyzv8ErCjLeWXnpLX7zgXhCoWI6 fZj2iCyfRdt/gOXQFuRi7Z0y0JLF0BFE9NXzjCn3+hfZRRNSlvKTDARP6SsSB9Qh 2G4DF0aoyLkQkPx5DeECMQ8u2xqin8t8IYcXz3BgeIGr0hm51DfankUYfK1XrCWR m2Rbhjr01DUjrQKIvacC5vvN/a2RrkRH4PTOK0e6lFqrAv0Ds23jW46L5XgCTL9s vtQqvJqmBqwetgsqgV3+s0t7UAFqHYQoQHHEO1dYsLf1otFeddq0Bj0J4jDrjDmg WuxJNZ6cbNcRJn3aOgF74pE8qGwb8adW8IECAwEAAaAAMA0GCSqGSIb3DQEBCwUA A4IBAQBtKJAZWhbNJMR0wDKEnnPK/2nsrPrfGVu9fO77Daew1FGhn4lw78GAequv Yg5zWOXx5aKlhFuYpzZLs5Jb1XqD8dk1it0iTi6xHGXXZB3RflchBJLElJMpEecQ 5Iicc9uc2nEQU2UorG64isXFh73W/dBkPXrx2EvX5Smo3de/fiMi546OGeMj025l f+JhuwuyAAOgOr0wqVavTA+2feOj3kyLOpVwAHTDkN+vyiWjIJtVuc8ORofZ8M5n LFm3qx47kOUlitF8fltd30ikzHSTXYiKSxBdDWbZ5SEAh9KPeJPk23j+iexddPyM TuczHYEKPFpTLR6Xzm/sAdhdppa2 -----END CERTIFICATE REQUEST----- INFO: Request: com.netscape.certsrv.cert.CertEnrollmentRequest@97c934a2 INFO: DNS names: null INFO: Requestor: KRA-master.redacted_domain.com-8443 INFO: HTTP request: POST /ca/ee/ca/profileSubmit HTTP/1.1 INFO: Content-Type: application/x-www-form-urlencoded INFO: Content-Length: 1229 INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: xmlOutput=true&cert_request_type=pkcs10&profileId=caInternalAuthDRMstorageCert&cert_request=-----BEGIN+CERTIFICATE+REQUEST-----%0AMIICgTCCAWkCAQAwPDEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMSAwHgYDVQQD%0ADBdLUkEgU3RvcmFnZSBDZXJ0aWZpY2F0ZTCCASIwDQYJKoZIhvcNAQEBBQADggEP%0AADCCAQoCggEBALvNjszq6QvI5RGs4wahPpjwtUyzv8ErCjLeWXnpLX7zgXhCoWI6%0AfZj2iCyfRdt%2FgOXQFuRi7Z0y0JLF0BFE9NXzjCn3%2BhfZRRNSlvKTDARP6SsSB9Qh%0A2G4DF0aoyLkQkPx5DeECMQ8u2xqin8t8IYcXz3BgeIGr0hm51DfankUYfK1XrCWR%0Am2Rbhjr01DUjrQKIvacC5vvN%2Fa2RrkRH4PTOK0e6lFqrAv0Ds23jW46L5XgCTL9s%0AvtQqvJqmBqwetgsqgV3%2Bs0t7UAFqHYQoQHHEO1dYsLf1otFeddq0Bj0J4jDrjDmg%0AWuxJNZ6cbNcRJn3aOgF74pE8qGwb8adW8IECAwEAAaAAMA0GCSqGSIb3DQEBCwUA%0AA4IBAQBtKJAZWhbNJMR0wDKEnnPK%2F2nsrPrfGVu9fO77Daew1FGhn4lw78GAequv%0AYg5zWOXx5aKlhFuYpzZLs5Jb1XqD8dk1it0iTi6xHGXXZB3RflchBJLElJMpEecQ%0A5Iicc9uc2nEQU2UorG64isXFh73W%2FdBkPXrx2EvX5Smo3de%2FfiMi546OGeMj025l%0Af%2BJhuwuyAAOgOr0wqVavTA%2B2feOj3kyLOpVwAHTDkN%2BvyiWjIJtVuc8ORofZ8M5n%0ALFm3qx47kOUlitF8fltd30ikzHSTXYiKSxBdDWbZ5SEAh9KPeJPk23j%2BiexddPyM%0ATuczHYEKPFpTLR6Xzm%2FsAdhdppa2%0A-----END+CERTIFICATE+REQUEST-----%0A&subject=cn%3DKRA+Storage+Certificate%2CO%3DREDACTED_DOMAIN.COM&requestor_name=KRA-master.redacted_domain.com-8443&sessionID=657561939077568930 INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:21 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Content-Type: application/xml INFO: Content-Length: 1618 INFO: Keep-Alive: timeout=30, max=98 INFO: Connection: Keep-Alive FINE: Response: 012CN=KRA Storage Certificate,O=REDACTED_DOMAIN.COMcMIID/jCCAmagAwIBAgIBDDANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MjFaFw0yNDEyMDYyMzU3MjFaMDwxGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEgMB4GA1UEAwwXS1JBIFN0b3JhZ2UgQ2VydGlmaWNhdGUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC7zY7M6ukLyOURrOMGoT6Y8LVMs7/BKwoy3ll56S1+84F4QqFiOn2Y9ogsn0Xbf4Dl0BbkYu2dMtCSxdARRPTV84wp9/oX2UUTUpbykwwET+krEgfUIdhuAxdGqMi5EJD8eQ3hAjEPLtsaop/LfCGHF89wYHiBq9IZudQ32p5FGHytV6wlkZtkW4Y69NQ1I60CiL2nAub7zf2tka5ER+D0zitHupRaqwL9A7Nt41uOi+V4Aky/bL7UKryapgasHrYLKoFd/rNLe1ABah2EKEBxxDtXWLC39aLRXnXatAY9CeIw64w5oFrsSTWenGzXESZ92joBe+KRPKhsG/GnVvCBAgMBAAGjgYwwgYkwHwYDVR0jBBgwFoAUnCHM6adwr08G/ZX+WF9+wfZnocYwQQYIKwYBBQUHAQEENTAzMDEGCCsGAQUFBzABhiVodHRwOi8vaXBhLWNhLm1vbml2YWdyb3VwLmNvbS9jYS9vY3NwMA4GA1UdDwEB/wQEAwIE8DATBgNVHSUEDDAKBggrBgEFBQcDAjANBgkqhkiG9w0BAQ0FAAOCAYEAgUqFtkAgrGwZ3+RVWH+wzqXh5yi+prd9dXTjRu5RMEERYxmBnBA1Hi7ZPKr4Jnow4gWIlSDN+ua0jTM2X1FzZk/TYUvAhpn3gi5WKATq68TXt7nhf9Qq/vc2hltUsiNkuuZ23FiY5ZZYc7IMki5lW91APE2WEEBoiizxzpC9NRBjaZhy4cBlv3sQr8sIkfaZhkwifwjIjYYHljZYq0iRHOiBPLxfWLlENkHCT2uhtsfGCnsmVizMbt0qlDn6c6jIHlCGqfdRqKmUqGJrsLq5uVHTJFD5qwdhwA6dhmKiXJq4RG4KH1W2QKiey9hpArRaZ5QfLoDAj4jPUm9i34Kst4mB8awKcrXsAyS1ZSOMjHA4l6XikWWJbu3G6Xnvvl8MeVbYxHfuNU73VXRdgdFA6xuCR2OQx9NlPBwRfs/L+FcGVDiYAC9LYJyuhPDkEMvWCQNSdcNiVsKsR9ZaloGA7p7TN8bHORZrUSsC8qrQDtG+UE6OjynNixCwiIODTFXf FINE: CACertClient: Response: 012CN=KRA Storage Certificate,O=REDACTED_DOMAIN.COMcMIID/jCCAmagAwIBAgIBDDANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MjFaFw0yNDEyMDYyMzU3MjFaMDwxGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEgMB4GA1UEAwwXS1JBIFN0b3JhZ2UgQ2VydGlmaWNhdGUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC7zY7M6ukLyOURrOMGoT6Y8LVMs7/BKwoy3ll56S1+84F4QqFiOn2Y9ogsn0Xbf4Dl0BbkYu2dMtCSxdARRPTV84wp9/oX2UUTUpbykwwET+krEgfUIdhuAxdGqMi5EJD8eQ3hAjEPLtsaop/LfCGHF89wYHiBq9IZudQ32p5FGHytV6wlkZtkW4Y69NQ1I60CiL2nAub7zf2tka5ER+D0zitHupRaqwL9A7Nt41uOi+V4Aky/bL7UKryapgasHrYLKoFd/rNLe1ABah2EKEBxxDtXWLC39aLRXnXatAY9CeIw64w5oFrsSTWenGzXESZ92joBe+KRPKhsG/GnVvCBAgMBAAGjgYwwgYkwHwYDVR0jBBgwFoAUnCHM6adwr08G/ZX+WF9+wfZnocYwQQYIKwYBBQUHAQEENTAzMDEGCCsGAQUFBzABhiVodHRwOi8vaXBhLWNhLm1vbml2YWdyb3VwLmNvbS9jYS9vY3NwMA4GA1UdDwEB/wQEAwIE8DATBgNVHSUEDDAKBggrBgEFBQcDAjANBgkqhkiG9w0BAQ0FAAOCAYEAgUqFtkAgrGwZ3+RVWH+wzqXh5yi+prd9dXTjRu5RMEERYxmBnBA1Hi7ZPKr4Jnow4gWIlSDN+ua0jTM2X1FzZk/TYUvAhpn3gi5WKATq68TXt7nhf9Qq/vc2hltUsiNkuuZ23FiY5ZZYc7IMki5lW91APE2WEEBoiizxzpC9NRBjaZhy4cBlv3sQr8sIkfaZhkwifwjIjYYHljZYq0iRHOiBPLxfWLlENkHCT2uhtsfGCnsmVizMbt0qlDn6c6jIHlCGqfdRqKmUqGJrsLq5uVHTJFD5qwdhwA6dhmKiXJq4RG4KH1W2QKiey9hpArRaZ5QfLoDAj4jPUm9i34Kst4mB8awKcrXsAyS1ZSOMjHA4l6XikWWJbu3G6Xnvvl8MeVbYxHfuNU73VXRdgdFA6xuCR2OQx9NlPBwRfs/L+FcGVDiYAC9LYJyuhPDkEMvWCQNSdcNiVsKsR9ZaloGA7p7TN8bHORZrUSsC8qrQDtG+UE6OjynNixCwiIODTFXf FINE: CACertClient: - status: 0 FINE: CACertClient: - request ID: 0xc FINE: CACertClient: - serial: c FINE: CACertClient: - cert: MIID/jCCAmagAwIBAgIBDDANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MjFaFw0yNDEyMDYyMzU3MjFaMDwxGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEgMB4GA1UEAwwXS1JBIFN0b3JhZ2UgQ2VydGlmaWNhdGUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC7zY7M6ukLyOURrOMGoT6Y8LVMs7/BKwoy3ll56S1+84F4QqFiOn2Y9ogsn0Xbf4Dl0BbkYu2dMtCSxdARRPTV84wp9/oX2UUTUpbykwwET+krEgfUIdhuAxdGqMi5EJD8eQ3hAjEPLtsaop/LfCGHF89wYHiBq9IZudQ32p5FGHytV6wlkZtkW4Y69NQ1I60CiL2nAub7zf2tka5ER+D0zitHupRaqwL9A7Nt41uOi+V4Aky/bL7UKryapgasHrYLKoFd/rNLe1ABah2EKEBxxDtXWLC39aLRXnXatAY9CeIw64w5oFrsSTWenGzXESZ92joBe+KRPKhsG/GnVvCBAgMBAAGjgYwwgYkwHwYDVR0jBBgwFoAUnCHM6adwr08G/ZX+WF9+wfZnocYwQQYIKwYBBQUHAQEENTAzMDEGCCsGAQUFBzABhiVodHRwOi8vaXBhLWNhLm1vbml2YWdyb3VwLmNvbS9jYS9vY3NwMA4GA1UdDwEB/wQEAwIE8DATBgNVHSUEDDAKBggrBgEFBQcDAjANBgkqhkiG9w0BAQ0FAAOCAYEAgUqFtkAgrGwZ3+RVWH+wzqXh5yi+prd9dXTjRu5RMEERYxmBnBA1Hi7ZPKr4Jnow4gWIlSDN+ua0jTM2X1FzZk/TYUvAhpn3gi5WKATq68TXt7nhf9Qq/vc2hltUsiNkuuZ23FiY5ZZYc7IMki5lW91APE2WEEBoiizxzpC9NRBjaZhy4cBlv3sQr8sIkfaZhkwifwjIjYYHljZYq0iRHOiBPLxfWLlENkHCT2uhtsfGCnsmVizMbt0qlDn6c6jIHlCGqfdRqKmUqGJrsLq5uVHTJFD5qwdhwA6dhmKiXJq4RG4KH1W2QKiey9hpArRaZ5QfLoDAj4jPUm9i34Kst4mB8awKcrXsAyS1ZSOMjHA4l6XikWWJbu3G6Xnvvl8MeVbYxHfuNU73VXRdgdFA6xuCR2OQx9NlPBwRfs/L+FcGVDiYAC9LYJyuhPDkEMvWCQNSdcNiVsKsR9ZaloGA7p7TN8bHORZrUSsC8qrQDtG+UE6OjynNixCwiIODTFXf INFO: - serial: 0xc INFO: Storing cert and request for storage INFO: Importing storage cert into NSS database DEBUG: NSSDatabase.add_cert(storageCert cert-pki-kra) DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmp9ewy0wp_/password.txt nss-cert-import --format PEM --debug storageCert cert-pki-kra INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Storing password into /tmp/nss-password-9142202814497480470.txt FINE: NSSDatabase: Command: certutil -A -d /etc/pki/pki-tomcat/alias -f /tmp/nss-password-9142202814497480470.txt -a -n "storageCert cert-pki-kra" -t ,, -i /tmp/nss-cert-13125294081903825752.crt INFO: Setting up sslserver cert DEBUG: PKISubsystem.get_subsystem_cert(sslserver) INFO: Getting sslserver cert info from CS.cfg DEBUG: PKISubsystem.get_nssdb_cert_info(sslserver) INFO: Getting sslserver cert info from NSS database DEBUG: NSSDatabase.get_cert_info(Server-Cert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(Server-Cert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmpe64wu5tg/password.txt -n Server-Cert cert-pki-ca -a DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(Server-Cert cert-pki-ca) ends DEBUG: NSSDatabase.get_trust(Server-Cert cert-pki-ca) DEBUG: fullname: Server-Cert cert-pki-ca DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmp8ygdgpyn/password.txt DEBUG: NSSDatabase.get_cert_info(Server-Cert cert-pki-ca) ends INFO: sslserver cert is already set up INFO: Setting up subsystem cert DEBUG: PKISubsystem.get_subsystem_cert(subsystem) INFO: Getting subsystem cert info from CS.cfg DEBUG: PKISubsystem.get_nssdb_cert_info(subsystem) INFO: Getting subsystem cert info from NSS database DEBUG: NSSDatabase.get_cert_info(subsystemCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmpb1wt41ts/password.txt -n subsystemCert cert-pki-ca -a DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) ends DEBUG: NSSDatabase.get_trust(subsystemCert cert-pki-ca) DEBUG: fullname: subsystemCert cert-pki-ca DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmprkfqxjo0/password.txt DEBUG: NSSDatabase.get_cert_info(subsystemCert cert-pki-ca) ends INFO: subsystem cert is already set up INFO: Setting up audit_signing cert DEBUG: PKISubsystem.get_subsystem_cert(audit_signing) INFO: Getting audit_signing cert info from CS.cfg DEBUG: PKISubsystem.get_nssdb_cert_info(audit_signing) INFO: Getting audit_signing cert info from NSS database DEBUG: NSSDatabase.get_cert_info(auditSigningCert cert-pki-kra) begins DEBUG: NSSDatabase.get_cert(auditSigningCert cert-pki-kra) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmpzeymvk9u/password.txt -n auditSigningCert cert-pki-kra -a DEBUG: Cert not found: auditSigningCert cert-pki-kra DEBUG: PKIDeployer.setup_system_cert() DEBUG: NSSDatabase.get_cert_info(auditSigningCert cert-pki-kra) begins DEBUG: NSSDatabase.get_cert(auditSigningCert cert-pki-kra) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmpduyzcn0t/password.txt -n auditSigningCert cert-pki-kra -a DEBUG: Cert not found: auditSigningCert cert-pki-kra INFO: audit_signing cert does not exist in NSS database INFO: Creating audit_signing key DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmprwj1upg8/password.txt nss-key-create --output-format json --key-type RSA --key-size 2048 --debug INFO: - key ID: 0x9eb4ddf7acaf1a9da725a3ff07a08e2d22142023 INFO: Creating audit_signing cert request DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmp9ewy0wp_/password.txt nss-cert-request --subject cn=KRA Audit,O=REDACTED_DOMAIN.COM --csr /tmp/tmpzznvx4qc/request.csr --key-id 0x9eb4ddf7acaf1a9da725a3ff07a08e2d22142023 --hash SHA256 --debug INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Loading key 0x9eb4ddf7acaf1a9da725a3ff07a08e2d22142023 FINE: NSSDatabase: - class: org.mozilla.jss.pkcs11.PK11RSAPrivateKey FINE: NSSDatabase: - algorithm: RSA FINE: NSSDatabase: - format: null FINE: NSSDatabase: - key type: RSA FINE: NSSDatabase: - size: 2048 FINE: NSSDatabase: Creating PKCS #10 request FINE: NSSDatabase: - subjecct: cn=KRA Audit,O=REDACTED_DOMAIN.COM FINE: NSSDatabase: - algorithm: SHA256withRSA FINE: CryptoUtil: Creating PKCS #10 request FINE: CryptoUtil: - algorithm: SHA256withRSA FINE: CryptoUtil: - subject: cn=KRA Audit,O=REDACTED_DOMAIN.COM FINE: CryptoUtil: - attributes: DEBUG: - request: MIICczCCAVsCAQAwLjEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMRIwEAYDVQQDDAlLUkEgQXVkaXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDIdtXAhWx3aFjSPBNUbEuh4Mfuw9EjUkRFvETKXUEokovohfwv1hNs8qAitqH/YLJd4dqIppaxOpukrw235EL74ujueab/c2ygiATR8SCWvx+KVAoTYYdAJ1wTzzjyfclPIz+PTJ0BCoPd/kDlJM+mN1s5TNtbwxmqGIhEE7RKOT8qXRQvVzDeZROjcW8M3WdhsHYQyhidazQ+rQFYilPKJ16VbhesaZ9lVZTUvouEJlu0D0l3DKUBQZw9+H1mbl0GR7YvPd68TVPOogFNibhMkzw2oaF6K8XKbgZ2qEup5u7BeMdi7MWAYQ163mzXXJz1VooRXwJec0idey9BwkuVAgMBAAGgADANBgkqhkiG9w0BAQsFAAOCAQEAoJj9cwZvKWyLh0D2LXFqpfrsS/mH/HtedmmeET+hLOvFIJ6/Y14VZiwwdGD2QuW9fVFlUjCeQjqB0eIxAIzRkGshFNPnwo2QZRjGP2WYLTd7vslaM5jHrEcvCSmgdO+PhSTkOFeMdqTw1Yu4S3Sj8n84zgYAzzFcSuqVPV+wJaydH/+43c+wXqnEVLNPXSMJUNt2g4M+erG+6lzWY0bbmDhDXlRfRTf++aCbPQDe+jqdvmxnzxBlkNu+7w3MmCKA39as/9o+59oT0gI4PV5zGhFv8l+T3rlb19XnySN84zTZ6CxBOA+xfjzjilKygV5cxLEfKKNaXYEY9II8QGskdQ== INFO: Requesting audit_signing cert from https://master.redacted_domain.com:443 DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -f /etc/pki/pki-tomcat/password.conf -U https://master.redacted_domain.com:443 --ignore-banner ca-cert-request-submit --request-type pkcs10 --csr-file /tmp/tmp1e87luf_/request.csr --profile caInternalAuthAuditSigningCert --subject cn=KRA Audit,O=REDACTED_DOMAIN.COM --requestor KRA-master.redacted_domain.com-8443 --install-token /tmp/tmp1e87luf_/install-token --output-format PEM --debug INFO: Retrieving caInternalAuthAuditSigningCert profile INFO: Connecting to https://master.redacted_domain.com:443 INFO: HTTP request: GET /pki/rest/info HTTP/1.1 INFO: Accept: application/json INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: INFO: Server certificate: CN=master.redacted_domain.com,O=REDACTED_DOMAIN.COM INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:28 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Set-Cookie: JSESSIONID=94AD384067DB6BA9CA362D2BE0408319; Path=/pki; Secure; HttpOnly INFO: Content-Type: application/json INFO: Content-Length: 50 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=100 INFO: Connection: Keep-Alive FINE: Response: {"Version":"11.2.0","Attributes":{"Attribute":[]}} INFO: Server Name: null INFO: Server Version: 11.2.0 INFO: HTTP request: GET /ca/rest/certrequests/profiles/caInternalAuthAuditSigningCert HTTP/1.1 INFO: Accept: application/json INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:28 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Content-Type: application/json INFO: Content-Length: 915 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=99 INFO: Connection: Keep-Alive FINE: Response: {"ProfileID":"caInternalAuthAuditSigningCert","Renewal":false,"RemoteHost":"","RemoteAddress":"","Input":[{"id":"i1","ClassID":"certReqInputImpl","Name":"Certificate Request Input","ConfigAttribute":[],"Attribute":[{"name":"cert_request_type","Value":"","Descriptor":{"Syntax":"cert_request_type","Description":"Certificate Request Type"}},{"name":"cert_request","Value":"","Descriptor":{"Syntax":"cert_request","Description":"Certificate Request"}}]},{"id":"i2","ClassID":"submitterInfoInputImpl","Name":"Requestor Information","ConfigAttribute":[],"Attribute":[{"name":"requestor_name","Value":"","Descriptor":{"Syntax":"string","Description":"Requestor Name"}},{"name":"requestor_email","Value":"","Descriptor":{"Syntax":"string","Description":"Requestor Email"}},{"name":"requestor_phone","Value":"","Descriptor":{"Syntax":"string","Description":"Requestor Phone"}}]}],"Output":[],"Attributes":{"Attribute":[]}} INFO: Request type: pkcs10 INFO: CSR: -----BEGIN CERTIFICATE REQUEST----- MIICczCCAVsCAQAwLjEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMRIwEAYDVQQD DAlLUkEgQXVkaXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDIdtXA hWx3aFjSPBNUbEuh4Mfuw9EjUkRFvETKXUEokovohfwv1hNs8qAitqH/YLJd4dqI ppaxOpukrw235EL74ujueab/c2ygiATR8SCWvx+KVAoTYYdAJ1wTzzjyfclPIz+P TJ0BCoPd/kDlJM+mN1s5TNtbwxmqGIhEE7RKOT8qXRQvVzDeZROjcW8M3WdhsHYQ yhidazQ+rQFYilPKJ16VbhesaZ9lVZTUvouEJlu0D0l3DKUBQZw9+H1mbl0GR7Yv Pd68TVPOogFNibhMkzw2oaF6K8XKbgZ2qEup5u7BeMdi7MWAYQ163mzXXJz1VooR XwJec0idey9BwkuVAgMBAAGgADANBgkqhkiG9w0BAQsFAAOCAQEAoJj9cwZvKWyL h0D2LXFqpfrsS/mH/HtedmmeET+hLOvFIJ6/Y14VZiwwdGD2QuW9fVFlUjCeQjqB 0eIxAIzRkGshFNPnwo2QZRjGP2WYLTd7vslaM5jHrEcvCSmgdO+PhSTkOFeMdqTw 1Yu4S3Sj8n84zgYAzzFcSuqVPV+wJaydH/+43c+wXqnEVLNPXSMJUNt2g4M+erG+ 6lzWY0bbmDhDXlRfRTf++aCbPQDe+jqdvmxnzxBlkNu+7w3MmCKA39as/9o+59oT 0gI4PV5zGhFv8l+T3rlb19XnySN84zTZ6CxBOA+xfjzjilKygV5cxLEfKKNaXYEY 9II8QGskdQ== -----END CERTIFICATE REQUEST----- INFO: Request: com.netscape.certsrv.cert.CertEnrollmentRequest@d57be7cf INFO: DNS names: null INFO: Requestor: KRA-master.redacted_domain.com-8443 INFO: HTTP request: POST /ca/ee/ca/profileSubmit HTTP/1.1 INFO: Content-Type: application/x-www-form-urlencoded INFO: Content-Length: 1235 INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: xmlOutput=true&cert_request_type=pkcs10&profileId=caInternalAuthAuditSigningCert&cert_request=-----BEGIN+CERTIFICATE+REQUEST-----%0AMIICczCCAVsCAQAwLjEYMBYGA1UECgwPTU9OSVZBR1JPVVAuQ09NMRIwEAYDVQQD%0ADAlLUkEgQXVkaXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDIdtXA%0AhWx3aFjSPBNUbEuh4Mfuw9EjUkRFvETKXUEokovohfwv1hNs8qAitqH%2FYLJd4dqI%0AppaxOpukrw235EL74ujueab%2Fc2ygiATR8SCWvx%2BKVAoTYYdAJ1wTzzjyfclPIz%2BP%0ATJ0BCoPd%2FkDlJM%2BmN1s5TNtbwxmqGIhEE7RKOT8qXRQvVzDeZROjcW8M3WdhsHYQ%0AyhidazQ%2BrQFYilPKJ16VbhesaZ9lVZTUvouEJlu0D0l3DKUBQZw9%2BH1mbl0GR7Yv%0APd68TVPOogFNibhMkzw2oaF6K8XKbgZ2qEup5u7BeMdi7MWAYQ163mzXXJz1VooR%0AXwJec0idey9BwkuVAgMBAAGgADANBgkqhkiG9w0BAQsFAAOCAQEAoJj9cwZvKWyL%0Ah0D2LXFqpfrsS%2FmH%2FHtedmmeET%2BhLOvFIJ6%2FY14VZiwwdGD2QuW9fVFlUjCeQjqB%0A0eIxAIzRkGshFNPnwo2QZRjGP2WYLTd7vslaM5jHrEcvCSmgdO%2BPhSTkOFeMdqTw%0A1Yu4S3Sj8n84zgYAzzFcSuqVPV%2BwJaydH%2F%2B43c%2BwXqnEVLNPXSMJUNt2g4M%2BerG%2B%0A6lzWY0bbmDhDXlRfRTf%2B%2BaCbPQDe%2BjqdvmxnzxBlkNu%2B7w3MmCKA39as%2F9o%2B59oT%0A0gI4PV5zGhFv8l%2BT3rlb19XnySN84zTZ6CxBOA%2BxfjzjilKygV5cxLEfKKNaXYEY%0A9II8QGskdQ%3D%3D%0A-----END+CERTIFICATE+REQUEST-----%0A&subject=cn%3DKRA+Audit%2CO%3DREDACTED_DOMAIN.COM&requestor_name=KRA-master.redacted_domain.com-8443&sessionID=657561939077568930 INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:28 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Content-Type: application/xml INFO: Content-Length: 1556 INFO: Keep-Alive: timeout=30, max=98 INFO: Connection: Keep-Alive FINE: Response: 013CN=KRA Audit,O=REDACTED_DOMAIN.COMdMIID2TCCAkGgAwIBAgIBDTANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MjhaFw0yNDEyMDYyMzU3MjhaMC4xGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTESMBAGA1UEAwwJS1JBIEF1ZGl0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyHbVwIVsd2hY0jwTVGxLoeDH7sPRI1JERbxEyl1BKJKL6IX8L9YTbPKgIrah/2CyXeHaiKaWsTqbpK8Nt+RC++Lo7nmm/3NsoIgE0fEglr8filQKE2GHQCdcE8848n3JTyM/j0ydAQqD3f5A5STPpjdbOUzbW8MZqhiIRBO0Sjk/Kl0UL1cw3mUTo3FvDN1nYbB2EMoYnWs0Pq0BWIpTyidelW4XrGmfZVWU1L6LhCZbtA9JdwylAUGcPfh9Zm5dBke2Lz3evE1TzqIBTYm4TJM8NqGheivFym4GdqhLqebuwXjHYuzFgGENet5s11yc9VaKEV8CXnNInXsvQcJLlQIDAQABo3YwdDAfBgNVHSMEGDAWgBScIczpp3CvTwb9lf5YX37B9mehxjBBBggrBgEFBQcBAQQ1MDMwMQYIKwYBBQUHMAGGJWh0dHA6Ly9pcGEtY2EubW9uaXZhZ3JvdXAuY29tL2NhL29jc3AwDgYDVR0PAQH/BAQDAgbAMA0GCSqGSIb3DQEBDQUAA4IBgQBrysfJsFdHeIHnOAP0xjshfLddCYj/UP88VO5m2UA26uLOBv9PPARM2aGgMTmyK2eAmExr7uDUJ3jHYEvTg8MxE/KC1D5VsG3U1nHQBiOEHATHMQYzZFZ/bpsjNjsB8CyjJnSQQTxsqi/M6Gkg0/GzbcArNrm35G61NiSbmRNCYfgZO8lURj0UvsNcXDpXxBGgAsiRKMx81xCcC61o4w3SPXIHpzPSJwL3gEGKdddp0+6Cf3ipFMima0W2OlSM1Q83VqZXOw6GQYV0dSQsJJyK/v5+b2MVLf0G4GahCLSC2UPvlj7IdcUfa1qWRKN/TH+ZXCpalxrxGPLxN9yJce1PtkzwJRJ0y/x2UNsLXvsidOg9er+ZohLy/5Hz412JTqMMxAvLX9yCMcxWOtBoIYgISIp0PLWqbSU4uaJJuLL/pasA5d4YCaE3RnjwXUzgSsBStKQeinxwHf3OyGEunpnowDP9bduA2RlF0fNcPE1Dl3ytVwNPcVNyXraIqErYZAk= FINE: CACertClient: Response: 013CN=KRA Audit,O=REDACTED_DOMAIN.COMdMIID2TCCAkGgAwIBAgIBDTANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MjhaFw0yNDEyMDYyMzU3MjhaMC4xGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTESMBAGA1UEAwwJS1JBIEF1ZGl0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyHbVwIVsd2hY0jwTVGxLoeDH7sPRI1JERbxEyl1BKJKL6IX8L9YTbPKgIrah/2CyXeHaiKaWsTqbpK8Nt+RC++Lo7nmm/3NsoIgE0fEglr8filQKE2GHQCdcE8848n3JTyM/j0ydAQqD3f5A5STPpjdbOUzbW8MZqhiIRBO0Sjk/Kl0UL1cw3mUTo3FvDN1nYbB2EMoYnWs0Pq0BWIpTyidelW4XrGmfZVWU1L6LhCZbtA9JdwylAUGcPfh9Zm5dBke2Lz3evE1TzqIBTYm4TJM8NqGheivFym4GdqhLqebuwXjHYuzFgGENet5s11yc9VaKEV8CXnNInXsvQcJLlQIDAQABo3YwdDAfBgNVHSMEGDAWgBScIczpp3CvTwb9lf5YX37B9mehxjBBBggrBgEFBQcBAQQ1MDMwMQYIKwYBBQUHMAGGJWh0dHA6Ly9pcGEtY2EubW9uaXZhZ3JvdXAuY29tL2NhL29jc3AwDgYDVR0PAQH/BAQDAgbAMA0GCSqGSIb3DQEBDQUAA4IBgQBrysfJsFdHeIHnOAP0xjshfLddCYj/UP88VO5m2UA26uLOBv9PPARM2aGgMTmyK2eAmExr7uDUJ3jHYEvTg8MxE/KC1D5VsG3U1nHQBiOEHATHMQYzZFZ/bpsjNjsB8CyjJnSQQTxsqi/M6Gkg0/GzbcArNrm35G61NiSbmRNCYfgZO8lURj0UvsNcXDpXxBGgAsiRKMx81xCcC61o4w3SPXIHpzPSJwL3gEGKdddp0+6Cf3ipFMima0W2OlSM1Q83VqZXOw6GQYV0dSQsJJyK/v5+b2MVLf0G4GahCLSC2UPvlj7IdcUfa1qWRKN/TH+ZXCpalxrxGPLxN9yJce1PtkzwJRJ0y/x2UNsLXvsidOg9er+ZohLy/5Hz412JTqMMxAvLX9yCMcxWOtBoIYgISIp0PLWqbSU4uaJJuLL/pasA5d4YCaE3RnjwXUzgSsBStKQeinxwHf3OyGEunpnowDP9bduA2RlF0fNcPE1Dl3ytVwNPcVNyXraIqErYZAk= FINE: CACertClient: - status: 0 FINE: CACertClient: - request ID: 0xd FINE: CACertClient: - serial: d FINE: CACertClient: - cert: MIID2TCCAkGgAwIBAgIBDTANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MjhaFw0yNDEyMDYyMzU3MjhaMC4xGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTESMBAGA1UEAwwJS1JBIEF1ZGl0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyHbVwIVsd2hY0jwTVGxLoeDH7sPRI1JERbxEyl1BKJKL6IX8L9YTbPKgIrah/2CyXeHaiKaWsTqbpK8Nt+RC++Lo7nmm/3NsoIgE0fEglr8filQKE2GHQCdcE8848n3JTyM/j0ydAQqD3f5A5STPpjdbOUzbW8MZqhiIRBO0Sjk/Kl0UL1cw3mUTo3FvDN1nYbB2EMoYnWs0Pq0BWIpTyidelW4XrGmfZVWU1L6LhCZbtA9JdwylAUGcPfh9Zm5dBke2Lz3evE1TzqIBTYm4TJM8NqGheivFym4GdqhLqebuwXjHYuzFgGENet5s11yc9VaKEV8CXnNInXsvQcJLlQIDAQABo3YwdDAfBgNVHSMEGDAWgBScIczpp3CvTwb9lf5YX37B9mehxjBBBggrBgEFBQcBAQQ1MDMwMQYIKwYBBQUHMAGGJWh0dHA6Ly9pcGEtY2EubW9uaXZhZ3JvdXAuY29tL2NhL29jc3AwDgYDVR0PAQH/BAQDAgbAMA0GCSqGSIb3DQEBDQUAA4IBgQBrysfJsFdHeIHnOAP0xjshfLddCYj/UP88VO5m2UA26uLOBv9PPARM2aGgMTmyK2eAmExr7uDUJ3jHYEvTg8MxE/KC1D5VsG3U1nHQBiOEHATHMQYzZFZ/bpsjNjsB8CyjJnSQQTxsqi/M6Gkg0/GzbcArNrm35G61NiSbmRNCYfgZO8lURj0UvsNcXDpXxBGgAsiRKMx81xCcC61o4w3SPXIHpzPSJwL3gEGKdddp0+6Cf3ipFMima0W2OlSM1Q83VqZXOw6GQYV0dSQsJJyK/v5+b2MVLf0G4GahCLSC2UPvlj7IdcUfa1qWRKN/TH+ZXCpalxrxGPLxN9yJce1PtkzwJRJ0y/x2UNsLXvsidOg9er+ZohLy/5Hz412JTqMMxAvLX9yCMcxWOtBoIYgISIp0PLWqbSU4uaJJuLL/pasA5d4YCaE3RnjwXUzgSsBStKQeinxwHf3OyGEunpnowDP9bduA2RlF0fNcPE1Dl3ytVwNPcVNyXraIqErYZAk= INFO: - serial: 0xd INFO: Storing cert and request for audit_signing INFO: Importing audit_signing cert into NSS database DEBUG: NSSDatabase.add_cert(auditSigningCert cert-pki-kra) DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -C /tmp/tmp9ewy0wp_/password.txt nss-cert-import --format PEM --debug auditSigningCert cert-pki-kra INFO: Initializing NSS INFO: Logging into internal token INFO: Using internal token FINE: NSSDatabase: Storing password into /tmp/nss-password-17382792251058639130.txt FINE: NSSDatabase: Command: certutil -A -d /etc/pki/pki-tomcat/alias -f /tmp/nss-password-17382792251058639130.txt -a -n "auditSigningCert cert-pki-kra" -t ,, -i /tmp/nss-cert-3789175469269486756.crt INFO: Setting up trust flags DEBUG: Command: certutil -M -d /etc/pki/pki-tomcat/alias -f /tmp/tmp9ewy0wp_/password.txt -n auditSigningCert cert-pki-kra -t u,u,Pu INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/kra/conf/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/kra/conf/registry.cfg INFO: Getting admin certificate DEBUG: PKIDeployer.get_admin_cert() DEBUG: PKIDeployer: pki_external_step_two: False INFO: Generating CSR for cn=ipa-ca-agent,O=REDACTED_DOMAIN.COM DEBUG: Command: certutil -R -d /var/lib/ipa/tmp-dvglda_f -s cn=ipa-ca-agent,O=REDACTED_DOMAIN.COM -k rsa -g 2048 -z /var/lib/ipa/tmp-dvglda_f/noise -f /root/.dogtag/pki-tomcat/kra/password.conf -o /var/lib/ipa/tmp-dvglda_f/admin_pkcs10.bin INFO: Removing /var/lib/ipa/tmp-dvglda_f/noise DEBUG: Command: rm -f /var/lib/ipa/tmp-dvglda_f/noise DEBUG: Command: BtoA /var/lib/ipa/tmp-dvglda_f/admin_pkcs10.bin /var/lib/ipa/tmp-dvglda_f/admin_pkcs10.bin.asc INFO: Requesting admin cert from https://master.redacted_domain.com:443 DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -f /etc/pki/pki-tomcat/password.conf -U https://master.redacted_domain.com:443 --ignore-banner ca-cert-request-submit --request-type pkcs10 --csr-file /tmp/tmp_2a5hm0q/request.csr --profile caAdminCert --subject cn=ipa-ca-agent,O=REDACTED_DOMAIN.COM --install-token /tmp/tmp_2a5hm0q/install-token --output-format PEM --debug INFO: Retrieving caAdminCert profile INFO: Connecting to https://master.redacted_domain.com:443 INFO: HTTP request: GET /pki/rest/info HTTP/1.1 INFO: Accept: application/json INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: INFO: Server certificate: CN=master.redacted_domain.com,O=REDACTED_DOMAIN.COM INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:33 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Set-Cookie: JSESSIONID=C5666B8BA7D30D0A42100192A7743C6C; Path=/pki; Secure; HttpOnly INFO: Content-Type: application/json INFO: Content-Length: 50 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=100 INFO: Connection: Keep-Alive FINE: Response: {"Version":"11.2.0","Attributes":{"Attribute":[]}} INFO: Server Name: null INFO: Server Version: 11.2.0 INFO: HTTP request: GET /ca/rest/certrequests/profiles/caAdminCert HTTP/1.1 INFO: Accept: application/json INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:33 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Content-Type: application/json INFO: Content-Length: 1088 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=99 INFO: Connection: Keep-Alive FINE: Response: {"ProfileID":"caAdminCert","Renewal":false,"RemoteHost":"","RemoteAddress":"","Input":[{"id":"i1","ClassID":"certReqInputImpl","Name":"Certificate Request Input","ConfigAttribute":[],"Attribute":[{"name":"cert_request_type","Value":"","Descriptor":{"Syntax":"cert_request_type","Description":"Certificate Request Type"}},{"name":"cert_request","Value":"","Descriptor":{"Syntax":"cert_request","Description":"Certificate Request"}}]},{"id":"i2","ClassID":"submitterInfoInputImpl","Name":"Requestor Information","ConfigAttribute":[],"Attribute":[{"name":"requestor_name","Value":"","Descriptor":{"Syntax":"string","Description":"Requestor Name"}},{"name":"requestor_email","Value":"","Descriptor":{"Syntax":"string","Description":"Requestor Email"}},{"name":"requestor_phone","Value":"","Descriptor":{"Syntax":"string","Description":"Requestor Phone"}}]},{"id":"i3","ClassID":"subjectDNInputImpl","Name":"Subject Name","ConfigAttribute":[],"Attribute":[{"name":"subject","Value":"","Descriptor":{"Syntax":"string","Description":"Subject Name"}}]}],"Output":[],"Attributes":{"Attribute":[]}} INFO: Request type: pkcs10 INFO: CSR: -----BEGIN CERTIFICATE REQUEST----- MIICdjCCAV4CAQAwMTEYMBYGA1UEChMPTU9OSVZBR1JPVVAuQ09NMRUwEwYDVQQD EwxpcGEtY2EtYWdlbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC4 zgWs5uAt+0vxFE5o2SRVVWMHJvHbjTAYqH09RESymbiWSzcjl/eVIbj19/AudP4Y hWuc2Eynrk0mBCEayawCcdWTH+motiOFNO6NTeSiwXb3ypy5HDC2C0gaMAykq5Fz tW4jDMaWQMbIq8IJ4CRbLnzgP5PMPRvzmqwZ4B0xNGk2gfbImWorDnBJeSZi8x5L acl2Nmk9lQoJMYBE198zUIQtyXkFpqAyB437wJidOVjRDWN7MrQUVTKPxjOqVkjr Z3u6NpwFAlm1VljHH2LG+KcDxbrYd0YuMCQQG27WV1z+tcmG3ebYeoYGWuyeSP0V Nt1xYgXj5CaJDm/UR7AtAgMBAAGgADANBgkqhkiG9w0BAQsFAAOCAQEAgvwaeUIc CKIqLOxfOXOb+lCSNQX0uupya1zP1rTPmjjIjIEwW599uwM8R1fZrBUGN+33qQM4 3bdmGqOPIJkGU4rMPhgRzETkOUrwnrRhtNtNtkvzEyY6qm7LGIoHzRPULKDXdsDv GsKv3S4SdYVl9QXO7dXNcahlbklhs3ztoAaAs05BmP3WbsUP1C6FvK5QVyuPk/i6 jsjpvnXXQIjiNviqzmCFi3C7vDtaAgUig32HOsEwSBMxJ3QbsfIWBdRso0OJKGPS 1HrwRJ02WhkgoJuHcMh0QLr34ct+EtbKoDKqRBRZeWSVUXO8HKJepuKYEN3A9Yv4 sGT1yrYBDLM+CQ== -----END CERTIFICATE REQUEST----- INFO: Subject Name: INFO: - subject: cn=ipa-ca-agent,O=REDACTED_DOMAIN.COM INFO: Request: com.netscape.certsrv.cert.CertEnrollmentRequest@896e7bb9 INFO: DNS names: null INFO: Requestor: null INFO: HTTP request: POST /ca/ee/ca/profileSubmit HTTP/1.1 INFO: Content-Type: application/x-www-form-urlencoded INFO: Content-Length: 1144 INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: xmlOutput=true&cert_request_type=pkcs10&profileId=caAdminCert&cert_request=-----BEGIN+CERTIFICATE+REQUEST-----%0AMIICdjCCAV4CAQAwMTEYMBYGA1UEChMPTU9OSVZBR1JPVVAuQ09NMRUwEwYDVQQD%0AEwxpcGEtY2EtYWdlbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC4%0AzgWs5uAt%2B0vxFE5o2SRVVWMHJvHbjTAYqH09RESymbiWSzcjl%2FeVIbj19%2FAudP4Y%0AhWuc2Eynrk0mBCEayawCcdWTH%2BmotiOFNO6NTeSiwXb3ypy5HDC2C0gaMAykq5Fz%0AtW4jDMaWQMbIq8IJ4CRbLnzgP5PMPRvzmqwZ4B0xNGk2gfbImWorDnBJeSZi8x5L%0Aacl2Nmk9lQoJMYBE198zUIQtyXkFpqAyB437wJidOVjRDWN7MrQUVTKPxjOqVkjr%0AZ3u6NpwFAlm1VljHH2LG%2BKcDxbrYd0YuMCQQG27WV1z%2BtcmG3ebYeoYGWuyeSP0V%0ANt1xYgXj5CaJDm%2FUR7AtAgMBAAGgADANBgkqhkiG9w0BAQsFAAOCAQEAgvwaeUIc%0ACKIqLOxfOXOb%2BlCSNQX0uupya1zP1rTPmjjIjIEwW599uwM8R1fZrBUGN%2B33qQM4%0A3bdmGqOPIJkGU4rMPhgRzETkOUrwnrRhtNtNtkvzEyY6qm7LGIoHzRPULKDXdsDv%0AGsKv3S4SdYVl9QXO7dXNcahlbklhs3ztoAaAs05BmP3WbsUP1C6FvK5QVyuPk%2Fi6%0AjsjpvnXXQIjiNviqzmCFi3C7vDtaAgUig32HOsEwSBMxJ3QbsfIWBdRso0OJKGPS%0A1HrwRJ02WhkgoJuHcMh0QLr34ct%2BEtbKoDKqRBRZeWSVUXO8HKJepuKYEN3A9Yv4%0AsGT1yrYBDLM%2BCQ%3D%3D%0A-----END+CERTIFICATE+REQUEST-----%0A&subject=cn%3Dipa-ca-agent%2CO%3DREDACTED_DOMAIN.COM&sessionID=657561939077568930 INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:33 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Content-Type: application/xml INFO: Content-Length: 1607 INFO: Keep-Alive: timeout=30, max=98 INFO: Connection: Keep-Alive FINE: Response: 014CN=ipa-ca-agent,O=REDACTED_DOMAIN.COMeMIID/TCCAmWgAwIBAgIBDjANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MzNaFw0yMzEyMTcyMzU3MzNaMDExGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEVMBMGA1UEAwwMaXBhLWNhLWFnZW50MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuM4FrObgLftL8RROaNkkVVVjBybx240wGKh9PUREspm4lks3I5f3lSG49ffwLnT+GIVrnNhMp65NJgQhGsmsAnHVkx/pqLYjhTTujU3kosF298qcuRwwtgtIGjAMpKuRc7VuIwzGlkDGyKvCCeAkWy584D+TzD0b85qsGeAdMTRpNoH2yJlqKw5wSXkmYvMeS2nJdjZpPZUKCTGARNffM1CELcl5BaagMgeN+8CYnTlY0Q1jezK0FFUyj8YzqlZI62d7ujacBQJZtVZYxx9ixvinA8W62HdGLjAkEBtu1ldc/rXJht3m2HqGBlrsnkj9FTbdcWIF4+QmiQ5v1EewLQIDAQABo4GWMIGTMB8GA1UdIwQYMBaAFJwhzOmncK9PBv2V/lhffsH2Z6HGMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL2lwYS1jYS5tb25pdmFncm91cC5jb20vY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBeAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMA0GCSqGSIb3DQEBDQUAA4IBgQBrkOsBEfVzZWYAYrtDg3xkKlJnZ2uU8tQwpre+8pJ3qsS+JNDF+uE+D2p2UsBCc+wnQkXTOG7+2shC6DiF6dAhIfd+fCFlfoYOkwlvEG8xWMjtCFSS2urf0D61Qml52qbjb+hMnFxj8ZNSvuZZTS8sYW/BqQZH0QyyDf0KPwp7jtXjgcDtsEauOUuKzHG7Po91/jkOwuJhP/jdzpL1wRVkKaKuUqWN1Eb1uH/FpAWiWDZLpAwBr4+Gl4xDRhvw6A83283DPHTlcAsJMRzPMAMgsLXDllwo8SvrU+ZnYtPnXunthCH1+Tn8k0sHtq3Yl7n6iyx8k8WAjmCLTQzZu2sIla20iolv/3wDL5Godgf41jcT5X4/fTDC12TNcZ/xmq7WbUxuD52HxZ9KQrQwzVf/giFGSFra3uI4HxB+MLx847O9ChTPCmCRDxYWAlKd9lxWYcH6UAheCdHlmBmjKbUCm2ZeXy4gKu15366xYKzYJzxProBDuS5ZP0Az3v7u3Gc= FINE: CACertClient: Response: 014CN=ipa-ca-agent,O=REDACTED_DOMAIN.COMeMIID/TCCAmWgAwIBAgIBDjANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MzNaFw0yMzEyMTcyMzU3MzNaMDExGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEVMBMGA1UEAwwMaXBhLWNhLWFnZW50MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuM4FrObgLftL8RROaNkkVVVjBybx240wGKh9PUREspm4lks3I5f3lSG49ffwLnT+GIVrnNhMp65NJgQhGsmsAnHVkx/pqLYjhTTujU3kosF298qcuRwwtgtIGjAMpKuRc7VuIwzGlkDGyKvCCeAkWy584D+TzD0b85qsGeAdMTRpNoH2yJlqKw5wSXkmYvMeS2nJdjZpPZUKCTGARNffM1CELcl5BaagMgeN+8CYnTlY0Q1jezK0FFUyj8YzqlZI62d7ujacBQJZtVZYxx9ixvinA8W62HdGLjAkEBtu1ldc/rXJht3m2HqGBlrsnkj9FTbdcWIF4+QmiQ5v1EewLQIDAQABo4GWMIGTMB8GA1UdIwQYMBaAFJwhzOmncK9PBv2V/lhffsH2Z6HGMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL2lwYS1jYS5tb25pdmFncm91cC5jb20vY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBeAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMA0GCSqGSIb3DQEBDQUAA4IBgQBrkOsBEfVzZWYAYrtDg3xkKlJnZ2uU8tQwpre+8pJ3qsS+JNDF+uE+D2p2UsBCc+wnQkXTOG7+2shC6DiF6dAhIfd+fCFlfoYOkwlvEG8xWMjtCFSS2urf0D61Qml52qbjb+hMnFxj8ZNSvuZZTS8sYW/BqQZH0QyyDf0KPwp7jtXjgcDtsEauOUuKzHG7Po91/jkOwuJhP/jdzpL1wRVkKaKuUqWN1Eb1uH/FpAWiWDZLpAwBr4+Gl4xDRhvw6A83283DPHTlcAsJMRzPMAMgsLXDllwo8SvrU+ZnYtPnXunthCH1+Tn8k0sHtq3Yl7n6iyx8k8WAjmCLTQzZu2sIla20iolv/3wDL5Godgf41jcT5X4/fTDC12TNcZ/xmq7WbUxuD52HxZ9KQrQwzVf/giFGSFra3uI4HxB+MLx847O9ChTPCmCRDxYWAlKd9lxWYcH6UAheCdHlmBmjKbUCm2ZeXy4gKu15366xYKzYJzxProBDuS5ZP0Az3v7u3Gc= FINE: CACertClient: - status: 0 FINE: CACertClient: - request ID: 0xe FINE: CACertClient: - serial: e FINE: CACertClient: - cert: MIID/TCCAmWgAwIBAgIBDjANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MzNaFw0yMzEyMTcyMzU3MzNaMDExGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEVMBMGA1UEAwwMaXBhLWNhLWFnZW50MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuM4FrObgLftL8RROaNkkVVVjBybx240wGKh9PUREspm4lks3I5f3lSG49ffwLnT+GIVrnNhMp65NJgQhGsmsAnHVkx/pqLYjhTTujU3kosF298qcuRwwtgtIGjAMpKuRc7VuIwzGlkDGyKvCCeAkWy584D+TzD0b85qsGeAdMTRpNoH2yJlqKw5wSXkmYvMeS2nJdjZpPZUKCTGARNffM1CELcl5BaagMgeN+8CYnTlY0Q1jezK0FFUyj8YzqlZI62d7ujacBQJZtVZYxx9ixvinA8W62HdGLjAkEBtu1ldc/rXJht3m2HqGBlrsnkj9FTbdcWIF4+QmiQ5v1EewLQIDAQABo4GWMIGTMB8GA1UdIwQYMBaAFJwhzOmncK9PBv2V/lhffsH2Z6HGMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL2lwYS1jYS5tb25pdmFncm91cC5jb20vY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBeAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMA0GCSqGSIb3DQEBDQUAA4IBgQBrkOsBEfVzZWYAYrtDg3xkKlJnZ2uU8tQwpre+8pJ3qsS+JNDF+uE+D2p2UsBCc+wnQkXTOG7+2shC6DiF6dAhIfd+fCFlfoYOkwlvEG8xWMjtCFSS2urf0D61Qml52qbjb+hMnFxj8ZNSvuZZTS8sYW/BqQZH0QyyDf0KPwp7jtXjgcDtsEauOUuKzHG7Po91/jkOwuJhP/jdzpL1wRVkKaKuUqWN1Eb1uH/FpAWiWDZLpAwBr4+Gl4xDRhvw6A83283DPHTlcAsJMRzPMAMgsLXDllwo8SvrU+ZnYtPnXunthCH1+Tn8k0sHtq3Yl7n6iyx8k8WAjmCLTQzZu2sIla20iolv/3wDL5Godgf41jcT5X4/fTDC12TNcZ/xmq7WbUxuD52HxZ9KQrQwzVf/giFGSFra3uI4HxB+MLx847O9ChTPCmCRDxYWAlKd9lxWYcH6UAheCdHlmBmjKbUCm2ZeXy4gKu15366xYKzYJzxProBDuS5ZP0Az3v7u3Gc= DEBUG: Admin cert: MIID/TCCAmWgAwIBAgIBDjANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MzNaFw0yMzEyMTcyMzU3MzNaMDExGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEVMBMGA1UEAwwMaXBhLWNhLWFnZW50MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuM4FrObgLftL8RROaNkkVVVjBybx240wGKh9PUREspm4lks3I5f3lSG49ffwLnT+GIVrnNhMp65NJgQhGsmsAnHVkx/pqLYjhTTujU3kosF298qcuRwwtgtIGjAMpKuRc7VuIwzGlkDGyKvCCeAkWy584D+TzD0b85qsGeAdMTRpNoH2yJlqKw5wSXkmYvMeS2nJdjZpPZUKCTGARNffM1CELcl5BaagMgeN+8CYnTlY0Q1jezK0FFUyj8YzqlZI62d7ujacBQJZtVZYxx9ixvinA8W62HdGLjAkEBtu1ldc/rXJht3m2HqGBlrsnkj9FTbdcWIF4+QmiQ5v1EewLQIDAQABo4GWMIGTMB8GA1UdIwQYMBaAFJwhzOmncK9PBv2V/lhffsH2Z6HGMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL2lwYS1jYS5tb25pdmFncm91cC5jb20vY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBeAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMA0GCSqGSIb3DQEBDQUAA4IBgQBrkOsBEfVzZWYAYrtDg3xkKlJnZ2uU8tQwpre+8pJ3qsS+JNDF+uE+D2p2UsBCc+wnQkXTOG7+2shC6DiF6dAhIfd+fCFlfoYOkwlvEG8xWMjtCFSS2urf0D61Qml52qbjb+hMnFxj8ZNSvuZZTS8sYW/BqQZH0QyyDf0KPwp7jtXjgcDtsEauOUuKzHG7Po91/jkOwuJhP/jdzpL1wRVkKaKuUqWN1Eb1uH/FpAWiWDZLpAwBr4+Gl4xDRhvw6A83283DPHTlcAsJMRzPMAMgsLXDllwo8SvrU+ZnYtPnXunthCH1+Tn8k0sHtq3Yl7n6iyx8k8WAjmCLTQzZu2sIla20iolv/3wDL5Godgf41jcT5X4/fTDC12TNcZ/xmq7WbUxuD52HxZ9KQrQwzVf/giFGSFra3uI4HxB+MLx847O9ChTPCmCRDxYWAlKd9lxWYcH6UAheCdHlmBmjKbUCm2ZeXy4gKu15366xYKzYJzxProBDuS5ZP0Az3v7u3Gc= INFO: Storing admin cert into /root/.dogtag/pki-tomcat/kra_admin.cert INFO: Importing admin cert into /var/lib/ipa/tmp-dvglda_f DEBUG: NSSDatabase.add_cert(ipa-ca-agent) DEBUG: Command: certutil -A -d /var/lib/ipa/tmp-dvglda_f -f /root/.dogtag/pki-tomcat/kra/password.conf -n ipa-ca-agent -a -i /root/.dogtag/pki-tomcat/kra_admin.cert -t ,, INFO: Exporting admin cert into /tmp/tmpyyq6fqgn INFO: Creating /tmp INFO: Exporting ipa-ca-agent cert and key into /tmp/tmpyyq6fqgn DEBUG: Command: pk12util -d /var/lib/ipa/tmp-dvglda_f -o /tmp/tmpyyq6fqgn -n ipa-ca-agent -w /root/.dogtag/pki-tomcat/kra/pkcs12_password.conf -k /root/.dogtag/pki-tomcat/kra/password.conf -c AES-128-CBC -C NONE INFO: Setting up admin user DEBUG: Command: /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/kra/webapps/kra/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI kra-user-add --full-name admin --email root@localhost --password-file /tmp/tmpl6435_2u/password.txt --type adminType --state 1 --debug admin FINE: SubsystemUserAddCLI: Loading /var/lib/pki/pki-tomcat/kra/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 636 FINE: LdapBoundConnFactory: secure: true FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:636 with basic auth as cn=Directory Manager FINE: ldapconn/PKISocketFactory.makeSSLSocket: begins FINE: PKIClientSocketListener.handshakeCompleted: begins FINE: PKIClientSocketListener: Handshake completed: FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_ESTABLISH FINE: SSL handshake happened FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 INFO: Adding uid=admin,ou=People,o=kra,o=ipaca FINE: UGSubsystem: - objectclass: [top, person, organizationalPerson, inetOrgPerson, cmsuser] FINE: UGSubsystem: - uid: admin FINE: UGSubsystem: - sn: admin FINE: UGSubsystem: - cn: admin FINE: UGSubsystem: - mail: root@localhost FINE: UGSubsystem: - userPassword: ******** FINE: UGSubsystem: - usertype: adminType FINE: UGSubsystem: - userstate: 1 INFO: Admin UID: null added User UID: admin FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection FINE: PKIClientSocketListener.alertReceived: begins FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert received: FINE: - reason: clientAlertReceived: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: PKIClientSocketListener.alertSent: begins FINE: PKIClientSocketListener.alertSent: got description:0 FINE: PKIClientSocketListener.alertSent: got reason:clientAlertSent: CLOSE_NOTIFY FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert sent: FINE: - reason: clientAlertSent: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - subject: SYSTEM FINE: - server port: 636 INFO: Adding admin into Data Recovery Manager Agents DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/kra/webapps/kra/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI kra-group-member-add --debug Data Recovery Manager Agents admin FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/kra/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 636 FINE: LdapBoundConnFactory: secure: true FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:636 with basic auth as cn=Directory Manager FINE: ldapconn/PKISocketFactory.makeSSLSocket: begins FINE: PKIClientSocketListener.handshakeCompleted: begins FINE: PKIClientSocketListener: Handshake completed: FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_ESTABLISH FINE: SSL handshake happened FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Data Recovery Manager Agents,ou=Groups,o=kra,o=ipaca FINE: description: Agents for Data Recovery Manager FINE: uniqueMember: uid=admin,ou=People,o=kra,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection FINE: PKIClientSocketListener.alertReceived: begins FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert received: FINE: - reason: clientAlertReceived: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: PKIClientSocketListener.alertSent: begins FINE: PKIClientSocketListener.alertSent: got description:0 FINE: PKIClientSocketListener.alertSent: got reason:clientAlertSent: CLOSE_NOTIFY FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert sent: FINE: - reason: clientAlertSent: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - subject: SYSTEM FINE: - server port: 636 INFO: Adding admin into Administrators DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/kra/webapps/kra/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI kra-group-member-add --debug Administrators admin FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/kra/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 636 FINE: LdapBoundConnFactory: secure: true FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:636 with basic auth as cn=Directory Manager FINE: ldapconn/PKISocketFactory.makeSSLSocket: begins FINE: PKIClientSocketListener.handshakeCompleted: begins FINE: PKIClientSocketListener: Handshake completed: FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_ESTABLISH FINE: SSL handshake happened FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Administrators,ou=Groups,o=kra,o=ipaca FINE: description: People who manage the Certificate System FINE: uniqueMember: uid=admin,ou=People,o=kra,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection FINE: PKIClientSocketListener.alertReceived: begins FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert received: FINE: - reason: clientAlertReceived: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: PKIClientSocketListener.alertSent: begins FINE: PKIClientSocketListener.alertSent: got description:0 FINE: PKIClientSocketListener.alertSent: got reason:clientAlertSent: CLOSE_NOTIFY FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert sent: FINE: - reason: clientAlertSent: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - subject: SYSTEM FINE: - server port: 636 INFO: Adding certificate for admin DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/kra/webapps/kra/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI kra-user-cert-add --format DER --debug admin FINE: SubsystemUserCertAddCLI: Loading /var/lib/pki/pki-tomcat/kra/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 636 FINE: LdapBoundConnFactory: secure: true FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:636 with basic auth as cn=Directory Manager FINE: ldapconn/PKISocketFactory.makeSSLSocket: begins FINE: PKIClientSocketListener.handshakeCompleted: begins FINE: PKIClientSocketListener: Handshake completed: FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_ESTABLISH FINE: SSL handshake happened FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: Admin UID: null added cert for User UID: admin. cert DN: CN=ipa-ca-agent,O=REDACTED_DOMAIN.COM serial number: 0xe FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection FINE: PKIClientSocketListener.alertReceived: begins FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert received: FINE: - reason: clientAlertReceived: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: PKIClientSocketListener.alertSent: begins FINE: PKIClientSocketListener.alertSent: got description:0 FINE: PKIClientSocketListener.alertSent: got reason:clientAlertSent: CLOSE_NOTIFY FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert sent: FINE: - reason: clientAlertSent: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - subject: SYSTEM FINE: - server port: 636 INFO: Joining security domain at https://master.redacted_domain.com:443 DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -f /etc/pki/pki-tomcat/password.conf -U https://master.redacted_domain.com:443 --ignore-banner securitydomain-join --install-token /tmp/tmp485iu3n0/install-token --type KRA --hostname master.redacted_domain.com --unsecure-port 80 --secure-port 443 --debug KRA master.redacted_domain.com 8443 INFO: Connecting to https://master.redacted_domain.com:443 INFO: HTTP request: GET /pki/rest/info HTTP/1.1 INFO: Accept: application/json INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: INFO: Server certificate: CN=master.redacted_domain.com,O=REDACTED_DOMAIN.COM INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:42 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Set-Cookie: JSESSIONID=67E17D03A06CF52274670F0603921B51; Path=/pki; Secure; HttpOnly INFO: Content-Type: application/json INFO: Content-Length: 50 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=100 INFO: Connection: Keep-Alive FINE: Response: {"Version":"11.2.0","Attributes":{"Attribute":[]}} INFO: Server Name: null INFO: Server Version: 11.2.0 INFO: HTTP request: POST /ca/admin/ca/updateDomainXML HTTP/1.1 INFO: Content-Type: application/x-www-form-urlencoded INFO: Content-Length: 214 INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: agentsport=443&eeclientauthsport=443&httpport=80&name=KRA+master.redacted_domain.com+8443&host=master.redacted_domain.com&clone=false&dm=false&sessionID=657561939077568930&list=KRAList&type=KRA&sport=443&adminsport=443 INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:42 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Content-Type: application/xml INFO: Content-Length: 99 INFO: Keep-Alive: timeout=30, max=99 INFO: Connection: Keep-Alive FINE: Response: 0 INFO: Status: 0 INFO: Updating KRA ranges DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/kra/webapps/kra/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI kra-range-update --debug FINE: SubsystemRangeUpdateCLI: Loading /var/lib/pki/pki-tomcat/kra/conf/CS.cfg FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:636 with basic auth as cn=Directory Manager FINE: ldapconn/PKISocketFactory.makeSSLSocket: begins FINE: PKIClientSocketListener.handshakeCompleted: begins FINE: PKIClientSocketListener: Handshake completed: FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_ESTABLISH FINE: SSL handshake happened INFO: Updating serial number range INFO: Updating request number range FINE: PKIClientSocketListener.alertReceived: begins FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert received: FINE: - reason: clientAlertReceived: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: PKIClientSocketListener.alertSent: begins FINE: PKIClientSocketListener.alertSent: got description:0 FINE: PKIClientSocketListener.alertSent: got reason:clientAlertSent: CLOSE_NOTIFY FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert sent: FINE: - reason: clientAlertSent: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - subject: SYSTEM FINE: - server port: 636 INFO: Adding CA-master.redacted_domain.com-443 user into KRA DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/kra/webapps/kra/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI kra-user-add --full-name CA-master.redacted_domain.com-443 --type agentType --state 1 --debug CA-master.redacted_domain.com-443 FINE: SubsystemUserAddCLI: Loading /var/lib/pki/pki-tomcat/kra/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 636 FINE: LdapBoundConnFactory: secure: true FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:636 with basic auth as cn=Directory Manager FINE: ldapconn/PKISocketFactory.makeSSLSocket: begins FINE: PKIClientSocketListener.handshakeCompleted: begins FINE: PKIClientSocketListener: Handshake completed: FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_ESTABLISH FINE: SSL handshake happened FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 INFO: Adding uid=CA-master.redacted_domain.com-443,ou=People,o=kra,o=ipaca FINE: UGSubsystem: - objectclass: [top, person, organizationalPerson, inetOrgPerson, cmsuser] FINE: UGSubsystem: - uid: CA-master.redacted_domain.com-443 FINE: UGSubsystem: - sn: CA-master.redacted_domain.com-443 FINE: UGSubsystem: - cn: CA-master.redacted_domain.com-443 FINE: UGSubsystem: - usertype: agentType FINE: UGSubsystem: - userstate: 1 INFO: Admin UID: null added User UID: CA-master.redacted_domain.com-443 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection FINE: PKIClientSocketListener.alertReceived: begins FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert received: FINE: - reason: clientAlertReceived: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: PKIClientSocketListener.alertSent: begins FINE: PKIClientSocketListener.alertSent: got description:0 FINE: PKIClientSocketListener.alertSent: got reason:clientAlertSent: CLOSE_NOTIFY FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert sent: FINE: - reason: clientAlertSent: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - subject: SYSTEM FINE: - server port: 636 INFO: Getting CA subsystem certificate from https://master.redacted_domain.com:443 DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -f /etc/pki/pki-tomcat/password.conf -U https://master.redacted_domain.com:443 --ignore-banner ca-cert-subsystem-export --debug INFO: Connecting to https://master.redacted_domain.com:443 INFO: HTTP request: GET /pki/rest/info HTTP/1.1 INFO: Accept: application/json INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: INFO: Server certificate: CN=master.redacted_domain.com,O=REDACTED_DOMAIN.COM INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:47 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Set-Cookie: JSESSIONID=6FEBA10F5B51C6C354714B7BB5A7D18F; Path=/pki; Secure; HttpOnly INFO: Content-Type: application/json INFO: Content-Length: 50 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=100 INFO: Connection: Keep-Alive FINE: Response: {"Version":"11.2.0","Attributes":{"Attribute":[]}} INFO: Server Name: null INFO: Server Version: 11.2.0 INFO: HTTP request: GET /ca/admin/ca/getSubsystemCert HTTP/1.1 INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:47 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Content-Type: application/json INFO: Content-Length: 1416 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=99 INFO: Connection: Keep-Alive FINE: Response: { "Response" : { "Status" : "0", "Cert" : "MIID8zCCAlugAwIBAgIBBDANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzUyNDdaFw0yNDEyMDYyMzUyNDdaMDExGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEVMBMGA1UEAwwMQ0EgU3Vic3lzdGVtMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzDhQEQu3Iog2ApJjeIw+3Ji8wkXchPrcTbhamSPANdcdqnUrurWxVaO2e2f+jtp0f/4hvgeJafc0hiTAGDQ/wUBHRM00iFrsVI7EuV7qsvnEm0O9NO/NrYJ8Ibx4wehr+/VKNObaRULAkS05ne6LLyel72IzmHwXwAQNRUfALBxPScEXhywcchXqTcOfKvoobwsZQg3Pl9N7SxjzHqBE/9YA7PvEaPyK1s49W91vxR7936QCEOI0uaEVcbiwSET+OgaTotDLgbAUlZ7rFFLBtyhLFEfxN7AC69Af8ll/RXw+PQFcO96jfCQhRWbRTYUVMVfXVFNUFH3zz5aDzga3wwIDAQABo4GMMIGJMB8GA1UdIwQYMBaAFJwhzOmncK9PBv2V/lhffsH2Z6HGMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL2lwYS1jYS5tb25pdmFncm91cC5jb20vY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBPAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDQYJKoZIhvcNAQENBQADggGBAHRdz+kAMX8554l6bISYdndnZHyVLe2JOOWYsRocpzMOb8nA3m/32/inEMjzlLL9oZ9Z8sKGltkHe51N/U+6Y2Vm6VPHcO2F4rfiX4vF5kLwFbdWrFm1+vzqT9sjDB1uh9pyxJc3I7TNBefhkThveuQ4ut4x+VbFNKt7MVfSl85GBA3qhT1j0oMwwNfwoAvzX4at1sEdhMUmd6zCXKozQfXV2Pn34yCvQIU2RWfu2nE2pcwQJ3f16Xa9yKOnbHGVqQF8lpsohTeLReZ4z8+X7vdVQ7W86G1pFjV51Z072XQpyFRwSHvxGXbG2WF4NZNhc4dR3cJ3CroPK7eeVXX7ZanKM4rwcDsKiW/+kvAp2XQGbHC+DEbU7iuoGIveYEWh53dYzglWpsxtyOGY+KWdrSTiMqKzNV7aSbUzzMsghMb62XDaPxuC2rBqPkHZxvdHfxXJSFnaF1YREWFbygMuMFcVIo3O4uaCIibBNukvJ9Il3NbYS1hUS7mZFXs7pTBhow==" } } INFO: Adding CA subsystem certificate into CA-master.redacted_domain.com-443 DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/kra/webapps/kra/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI kra-user-cert-add --format PEM --debug CA-master.redacted_domain.com-443 FINE: SubsystemUserCertAddCLI: Loading /var/lib/pki/pki-tomcat/kra/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 636 FINE: LdapBoundConnFactory: secure: true FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:636 with basic auth as cn=Directory Manager FINE: ldapconn/PKISocketFactory.makeSSLSocket: begins FINE: PKIClientSocketListener.handshakeCompleted: begins FINE: PKIClientSocketListener: Handshake completed: FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_ESTABLISH FINE: SSL handshake happened FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 INFO: Admin UID: null added cert for User UID: CA-master.redacted_domain.com-443. cert DN: CN=CA Subsystem,O=REDACTED_DOMAIN.COM serial number: 0x4 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection FINE: PKIClientSocketListener.alertReceived: begins FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert received: FINE: - reason: clientAlertReceived: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: PKIClientSocketListener.alertSent: begins FINE: PKIClientSocketListener.alertSent: got description:0 FINE: PKIClientSocketListener.alertSent: got reason:clientAlertSent: CLOSE_NOTIFY FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert sent: FINE: - reason: clientAlertSent: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - subject: SYSTEM FINE: - server port: 636 INFO: Adding CA-master.redacted_domain.com-443 into Trusted Managers DEBUG: Command: /usr/sbin/runuser -u pkiuser -- /usr/lib/jvm/jre-17-openjdk/bin/java -classpath /usr/share/tomcat/bin/tomcat-juli.jar:/usr/share/java/tomcat-servlet-api.jar:/usr/share/pki/kra/webapps/kra/WEB-INF/lib/*:/var/lib/pki/pki-tomcat/common/lib/*:/usr/share/pki/lib/* -Djavax.sql.DataSource.Factory=org.apache.commons.dbcp.BasicDataSourceFactory -Dcatalina.base=/var/lib/pki/pki-tomcat -Dcatalina.home=/usr/share/tomcat -Djava.endorsed.dirs= -Djava.io.tmpdir=/var/lib/pki/pki-tomcat/temp -Djava.util.logging.config.file=/var/lib/pki/pki-tomcat/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Dcom.redhat.fips=false org.dogtagpki.server.cli.PKIServerCLI kra-group-member-add --debug Trusted Managers CA-master.redacted_domain.com-443 FINE: SubsystemGroupMemberAddCLI: Loading /var/lib/pki/pki-tomcat/kra/conf/CS.cfg FINE: Setting internaldb.minConns=1 FINE: PlainPasswordFile: Initializing PlainPasswordFile FINE: PlainPasswordFile: - internal: ******** FINE: PlainPasswordFile: - internaldb: ******** FINE: PlainPasswordFile: - replicationdb: ******** FINE: Creating LdapBoundConnFactor(UGSubsystem) FINE: LdapBoundConnFactory: initialization FINE: LdapAuthInfo: init() FINE: LdapAuthInfo: init begins FINE: LdapAuthInfo: init ends FINE: LdapBoundConnFactory: doCloning: true FINE: LdapBoundConnFactory: mininum: 1 FINE: LdapBoundConnFactory: maximum: 15 FINE: LdapBoundConnFactory: host: master.redacted_domain.com FINE: LdapBoundConnFactory: port: 636 FINE: LdapBoundConnFactory: secure: true FINE: LdapBoundConnFactory: authentication: 1 FINE: LdapBoundConnFactory: makeConnection(false) FINE: TCP Keep-Alive: true FINE: LdapAuthInfo: init: prompt is internaldb FINE: LdapAuthInfo: init: try getting from memory cache FINE: LdapAuthInfo: init: password not in memory FINE: LdapAuthInfo: getPasswordFromStore: try to get it from password store FINE: LdapAuthInfo: getPasswordFromStore: about to get from passwored store: internaldb FINE: LdapAuthInfo: getPasswordFromStore: password store available FINE: LdapAuthInfo: getPasswordFromStore: password found for prompt in password store FINE: LdapAuthInfo: password ok: store in memory cache FINE: LdapBoundConnection: Connecting to master.redacted_domain.com:636 with basic auth as cn=Directory Manager FINE: ldapconn/PKISocketFactory.makeSSLSocket: begins FINE: PKIClientSocketListener.handshakeCompleted: begins FINE: PKIClientSocketListener: Handshake completed: FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_ESTABLISH FINE: SSL handshake happened FINE: LdapBoundConnFactory.makeMinimum: begins: total connections: 0 FINE: LdapBoundConnFactory.makeMinimum: begins: available connections: 0 FINE: LdapBoundConnFactory.makeMinimum: increasing minimum connections by 1 FINE: LdapBoundConnFactory.makeMinimum: ends: total connections: 1 FINE: LdapBoundConnFactory.makeMinimum: ends: number of connections: 1 FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: dn: cn=Trusted Managers,ou=Groups,o=kra,o=ipaca FINE: description: Managers trusted by this PKI instance FINE: uniqueMember: uid=CA-master.redacted_domain.com-443,ou=People,o=kra,o=ipaca FINE: LdapBoundConnFactory: getting a connection FINE: LdapBoundConnFactory: master connection is connected: true FINE: LdapBoundConnFactory: connection already connected: true FINE: LdapBoundConnFactory: number of connections: 0 FINE: LdapBoundConnFactory: number of connections: 1 FINE: Destroying LdapBoundConnFactory(UGSubsystem) FINE: LdapBoundConnFactory: disconnecting master connection FINE: PKIClientSocketListener.alertReceived: begins FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert received: FINE: - reason: clientAlertReceived: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - server port: 636 FINE: - subject: SYSTEM FINE: PKIClientSocketListener.alertSent: begins FINE: PKIClientSocketListener.alertSent: got description:0 FINE: PKIClientSocketListener.alertSent: got reason:clientAlertSent: CLOSE_NOTIFY FINE: SignedAuditLogger: event CLIENT_ACCESS_SESSION_TERMINATED FINE: PKIClientSocketListener: SSL alert sent: FINE: - reason: clientAlertSent: CLOSE_NOTIFY FINE: - client: 172.16.0.21 FINE: - server: 172.16.0.21 FINE: - subject: SYSTEM FINE: - server port: 636 INFO: Adding KRA connector in CA DEBUG: PKISubsystem.get_subsystem_cert(subsystem) INFO: Getting subsystem cert info from CS.cfg DEBUG: PKISubsystem.get_nssdb_cert_info(subsystem) INFO: Getting subsystem cert info from NSS database DEBUG: NSSDatabase.get_cert_info(subsystemCert cert-pki-ca) begins DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) begins DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmppjjcntpt/password.txt -n subsystemCert cert-pki-ca -a DEBUG: certutil returned cert data DEBUG: NSSDatabase.get_cert(subsystemCert cert-pki-ca) ends DEBUG: NSSDatabase.get_trust(subsystemCert cert-pki-ca) DEBUG: fullname: subsystemCert cert-pki-ca DEBUG: Command: certutil -L -d /etc/pki/pki-tomcat/alias -f /tmp/tmps_gmv5ip/password.txt DEBUG: NSSDatabase.get_cert_info(subsystemCert cert-pki-ca) ends DEBUG: Command: pki -d /etc/pki/pki-tomcat/alias -f /etc/pki/pki-tomcat/password.conf -U https://master.redacted_domain.com:443 --ignore-banner ca-kraconnector-add --url https://master.redacted_domain.com:8443/kra/agent/kra/connector --subsystem-cert /tmp/tmp74tx4fmh/subsystem.crt --transport-cert /tmp/tmp74tx4fmh/transport.crt --transport-nickname transportCert cert-pki-kra --install-token /tmp/tmp74tx4fmh/install-token --debug INFO: Connecting to https://master.redacted_domain.com:443 INFO: HTTP request: GET /pki/rest/info HTTP/1.1 INFO: Accept: application/json INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: INFO: Server certificate: CN=master.redacted_domain.com,O=REDACTED_DOMAIN.COM INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:51 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Set-Cookie: JSESSIONID=C1BF0C41A4678E983DE71C77CCFF214C; Path=/pki; Secure; HttpOnly INFO: Content-Type: application/json INFO: Content-Length: 50 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=100 INFO: Connection: Keep-Alive FINE: Response: {"Version":"11.2.0","Attributes":{"Attribute":[]}} INFO: Server Name: null INFO: Server Version: 11.2.0 FINE: CAClient: content: {ca.connector.KRA.host=[master.redacted_domain.com], ca.connector.KRA.timeout=[30], ca.connector.KRA.transportCertNickname=[transportCert cert-pki-kra], ca.connector.KRA.port=[8443], ca.connector.KRA.subsystemCert=[MIID8zCCAlugAwIBAgIBBDANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzUyNDdaFw0yNDEyMDYyMzUyNDdaMDExGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEVMBMGA1UEAwwMQ0EgU3Vic3lzdGVtMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzDhQEQu3Iog2ApJjeIw+3Ji8wkXchPrcTbhamSPANdcdqnUrurWxVaO2e2f+jtp0f/4hvgeJafc0hiTAGDQ/wUBHRM00iFrsVI7EuV7qsvnEm0O9NO/NrYJ8Ibx4wehr+/VKNObaRULAkS05ne6LLyel72IzmHwXwAQNRUfALBxPScEXhywcchXqTcOfKvoobwsZQg3Pl9N7SxjzHqBE/9YA7PvEaPyK1s49W91vxR7936QCEOI0uaEVcbiwSET+OgaTotDLgbAUlZ7rFFLBtyhLFEfxN7AC69Af8ll/RXw+PQFcO96jfCQhRWbRTYUVMVfXVFNUFH3zz5aDzga3wwIDAQABo4GMMIGJMB8GA1UdIwQYMBaAFJwhzOmncK9PBv2V/lhffsH2Z6HGMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL2lwYS1jYS5tb25pdmFncm91cC5jb20vY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBPAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDQYJKoZIhvcNAQENBQADggGBAHRdz+kAMX8554l6bISYdndnZHyVLe2JOOWYsRocpzMOb8nA3m/32/inEMjzlLL9oZ9Z8sKGltkHe51N/U+6Y2Vm6VPHcO2F4rfiX4vF5kLwFbdWrFm1+vzqT9sjDB1uh9pyxJc3I7TNBefhkThveuQ4ut4x+VbFNKt7MVfSl85GBA3qhT1j0oMwwNfwoAvzX4at1sEdhMUmd6zCXKozQfXV2Pn34yCvQIU2RWfu2nE2pcwQJ3f16Xa9yKOnbHGVqQF8lpsohTeLReZ4z8+X7vdVQ7W86G1pFjV51Z072XQpyFRwSHvxGXbG2WF4NZNhc4dR3cJ3CroPK7eeVXX7ZanKM4rwcDsKiW/+kvAp2XQGbHC+DEbU7iuoGIveYEWh53dYzglWpsxtyOGY+KWdrSTiMqKzNV7aSbUzzMsghMb62XDaPxuC2rBqPkHZxvdHfxXJSFnaF1YREWFbygMuMFcVIo3O4uaCIibBNukvJ9Il3NbYS1hUS7mZFXs7pTBhow==], ca.connector.KRA.enable=[true], ca.connector.KRA.local=[false], sessionID=[657561939077568930], ca.connector.KRA.transportCert=[MIIEADCCAmigAwIBAgIBCzANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MTRaFw0yNDEyMDYyMzU3MTRaMD4xGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEiMCAGA1UEAwwZS1JBIFRyYW5zcG9ydCBDZXJ0aWZpY2F0ZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALLY874IfRaTqEdsujArLR23Nk9tfU4cezGFpczEsMPXdg8TJGuMhxrMyqpzqRe4oQMQVNM2Quxi0ZlpJrRUOwp/TOkhZK/cYR5wEux9kA7LU2/cBDJAu4KWZOshysH81gdN8/OJ0KHbJKNkDMHMQ1Ft5t7/IyR9EdChuVbcVYpJT2uXjhZRnEZ5635gipDVPsJ3UiF8SXXKf++5d2I1CEv3VHQJN1YBCCRMxTRaZQIsrIc0LABPwEKOe0N9LuWSsUNggZcNxNsEUs8NBS+3mucYRyrQ76D3qKG9gdGJt+ypX8L3fDFSr6xgy6Ku6ibWJ+xUCJM/ksD5VFS2k9d/uwMCAwEAAaOBjDCBiTAfBgNVHSMEGDAWgBScIczpp3CvTwb9lf5YX37B9mehxjBBBggrBgEFBQcBAQQ1MDMwMQYIKwYBBQUHMAGGJWh0dHA6Ly9pcGEtY2EubW9uaXZhZ3JvdXAuY29tL2NhL29jc3AwDgYDVR0PAQH/BAQDAgTwMBMGA1UdJQQMMAoGCCsGAQUFBwMCMA0GCSqGSIb3DQEBDQUAA4IBgQBC+olBeGrdYxTMQGsxRVmYSxiM2RuT09L0eTL3nxn6S/UZhKGH7NeoipaTPHezq/cxZAT0INLfpt6iWMjRgCS8jCCQpckyjB/C7qU3JPx8aAm+OevYwe6Zgy7CqiNxPdn9r/BE6IVHCVjhUC8TFsICkLFL5Y4v1q+ZeocAcO6w+vrfeS14ajRDH6/1nE1unTfaXgFG6tdgc2Cmye8mWOZVgRytb6KZdYFC93x7ab0OlHry07ip0IjLAn941+vpIXy8CHXE74/3R9huLL51s0mB2JAq/uBk3724Q4rB58I/PRrl2EHnZQRb8zMZsTjqFtQWtDNPoVvD/UDIgyqJ/A+QKAx9sK+XWEwNZdw+t54JpkEduXtFwXNp5yxHSuaQOqf1IfG5svbmW9V25Dr0J2AgaIU4z8xgJwk7QM77TU63tzfjwBYvhrLolXSf1OMXBD8feIZsr91h8HvQccARSZmAo96tnSbC6finiQ3tUzO7bmb8Fzk3yyfr13aqb2yQybc=], ca.connector.KRA.uri=[/kra/agent/kra/connector]} INFO: HTTP request: POST /ca/admin/ca/updateConnector HTTP/1.1 INFO: Content-Type: application/x-www-form-urlencoded INFO: Content-Length: 3216 INFO: Host: master.redacted_domain.com:443 INFO: Connection: Keep-Alive INFO: User-Agent: Apache-HttpClient/4.5.13 (Java/17.0.5) FINE: Request: ca.connector.KRA.host=master.redacted_domain.com&ca.connector.KRA.timeout=30&ca.connector.KRA.transportCertNickname=transportCert+cert-pki-kra&ca.connector.KRA.port=8443&ca.connector.KRA.subsystemCert=MIID8zCCAlugAwIBAgIBBDANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzUyNDdaFw0yNDEyMDYyMzUyNDdaMDExGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEVMBMGA1UEAwwMQ0EgU3Vic3lzdGVtMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzDhQEQu3Iog2ApJjeIw%2B3Ji8wkXchPrcTbhamSPANdcdqnUrurWxVaO2e2f%2Bjtp0f%2F4hvgeJafc0hiTAGDQ%2FwUBHRM00iFrsVI7EuV7qsvnEm0O9NO%2FNrYJ8Ibx4wehr%2B%2FVKNObaRULAkS05ne6LLyel72IzmHwXwAQNRUfALBxPScEXhywcchXqTcOfKvoobwsZQg3Pl9N7SxjzHqBE%2F9YA7PvEaPyK1s49W91vxR7936QCEOI0uaEVcbiwSET%2BOgaTotDLgbAUlZ7rFFLBtyhLFEfxN7AC69Af8ll%2FRXw%2BPQFcO96jfCQhRWbRTYUVMVfXVFNUFH3zz5aDzga3wwIDAQABo4GMMIGJMB8GA1UdIwQYMBaAFJwhzOmncK9PBv2V%2FlhffsH2Z6HGMEEGCCsGAQUFBwEBBDUwMzAxBggrBgEFBQcwAYYlaHR0cDovL2lwYS1jYS5tb25pdmFncm91cC5jb20vY2Evb2NzcDAOBgNVHQ8BAf8EBAMCBPAwEwYDVR0lBAwwCgYIKwYBBQUHAwIwDQYJKoZIhvcNAQENBQADggGBAHRdz%2BkAMX8554l6bISYdndnZHyVLe2JOOWYsRocpzMOb8nA3m%2F32%2FinEMjzlLL9oZ9Z8sKGltkHe51N%2FU%2B6Y2Vm6VPHcO2F4rfiX4vF5kLwFbdWrFm1%2BvzqT9sjDB1uh9pyxJc3I7TNBefhkThveuQ4ut4x%2BVbFNKt7MVfSl85GBA3qhT1j0oMwwNfwoAvzX4at1sEdhMUmd6zCXKozQfXV2Pn34yCvQIU2RWfu2nE2pcwQJ3f16Xa9yKOnbHGVqQF8lpsohTeLReZ4z8%2BX7vdVQ7W86G1pFjV51Z072XQpyFRwSHvxGXbG2WF4NZNhc4dR3cJ3CroPK7eeVXX7ZanKM4rwcDsKiW%2F%2BkvAp2XQGbHC%2BDEbU7iuoGIveYEWh53dYzglWpsxtyOGY%2BKWdrSTiMqKzNV7aSbUzzMsghMb62XDaPxuC2rBqPkHZxvdHfxXJSFnaF1YREWFbygMuMFcVIo3O4uaCIibBNukvJ9Il3NbYS1hUS7mZFXs7pTBhow%3D%3D&ca.connector.KRA.enable=true&ca.connector.KRA.local=false&sessionID=657561939077568930&ca.connector.KRA.transportCert=MIIEADCCAmigAwIBAgIBCzANBgkqhkiG9w0BAQ0FADA6MRgwFgYDVQQKDA9NT05JVkFHUk9VUC5DT00xHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjEyMTcyMzU3MTRaFw0yNDEyMDYyMzU3MTRaMD4xGDAWBgNVBAoMD01PTklWQUdST1VQLkNPTTEiMCAGA1UEAwwZS1JBIFRyYW5zcG9ydCBDZXJ0aWZpY2F0ZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALLY874IfRaTqEdsujArLR23Nk9tfU4cezGFpczEsMPXdg8TJGuMhxrMyqpzqRe4oQMQVNM2Quxi0ZlpJrRUOwp%2FTOkhZK%2FcYR5wEux9kA7LU2%2FcBDJAu4KWZOshysH81gdN8%2FOJ0KHbJKNkDMHMQ1Ft5t7%2FIyR9EdChuVbcVYpJT2uXjhZRnEZ5635gipDVPsJ3UiF8SXXKf%2B%2B5d2I1CEv3VHQJN1YBCCRMxTRaZQIsrIc0LABPwEKOe0N9LuWSsUNggZcNxNsEUs8NBS%2B3mucYRyrQ76D3qKG9gdGJt%2BypX8L3fDFSr6xgy6Ku6ibWJ%2BxUCJM%2FksD5VFS2k9d%2FuwMCAwEAAaOBjDCBiTAfBgNVHSMEGDAWgBScIczpp3CvTwb9lf5YX37B9mehxjBBBggrBgEFBQcBAQQ1MDMwMQYIKwYBBQUHMAGGJWh0dHA6Ly9pcGEtY2EubW9uaXZhZ3JvdXAuY29tL2NhL29jc3AwDgYDVR0PAQH%2FBAQDAgTwMBMGA1UdJQQMMAoGCCsGAQUFBwMCMA0GCSqGSIb3DQEBDQUAA4IBgQBC%2BolBeGrdYxTMQGsxRVmYSxiM2RuT09L0eTL3nxn6S%2FUZhKGH7NeoipaTPHezq%2FcxZAT0INLfpt6iWMjRgCS8jCCQpckyjB%2FC7qU3JPx8aAm%2BOevYwe6Zgy7CqiNxPdn9r%2FBE6IVHCVjhUC8TFsICkLFL5Y4v1q%2BZeocAcO6w%2BvrfeS14ajRDH6%2F1nE1unTfaXgFG6tdgc2Cmye8mWOZVgRytb6KZdYFC93x7ab0OlHry07ip0IjLAn941%2BvpIXy8CHXE74%2F3R9huLL51s0mB2JAq%2FuBk3724Q4rB58I%2FPRrl2EHnZQRb8zMZsTjqFtQWtDNPoVvD%2FUDIgyqJ%2FA%2BQKAx9sK%2BXWEwNZdw%2Bt54JpkEduXtFwXNp5yxHSuaQOqf1IfG5svbmW9V25Dr0J2AgaIU4z8xgJwk7QM77TU63tzfjwBYvhrLolXSf1OMXBD8feIZsr91h8HvQccARSZmAo96tnSbC6finiQ3tUzO7bmb8Fzk3yyfr13aqb2yQybc%3D&ca.connector.KRA.uri=%2Fkra%2Fagent%2Fkra%2Fconnector INFO: HTTP response: HTTP/1.1 200 200 INFO: Date: Sat, 17 Dec 2022 23:57:52 GMT INFO: Server: Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5 mod_wsgi/4.9.1 Python/3.11 mod_auth_gssapi/1.6.3 INFO: Content-Type: application/json INFO: Content-Length: 43 INFO: Vary: Accept-Encoding INFO: Keep-Alive: timeout=30, max=99 INFO: Connection: Keep-Alive FINE: Response: { "Response" : { "Status" : "0" } } FINE: CAClient: Response: { "Response" : { "Status" : "0" } } FINE: CAClient: status: 0 FINE: CAClient: Connector updated INFO: Storing subsystem config: /var/lib/pki/pki-tomcat/kra/conf/CS.cfg INFO: Storing registry config: /var/lib/pki/pki-tomcat/kra/conf/registry.cfg INFO: KRA configuration complete INFO: Restarting KRA subsystem INFO: Removing /etc/pki/pki-tomcat/Catalina/localhost/kra.xml DEBUG: Command: rm -rf /etc/pki/pki-tomcat/Catalina/localhost/kra.xml INFO: Waiting for web application to stop INFO: Web application stopped INFO: Creating /etc/pki/pki-tomcat/Catalina/localhost/kra.xml INFO: Waiting for web application to start INFO: Web application started INFO: Waiting for KRA subsystem INFO: Subsystem status: running INFO: Finalizing subsystem creation INFO: Loading instance: pki-tomcat INFO: Loading global Tomcat config: /etc/tomcat/tomcat.conf INFO: Loading PKI Tomcat config: /usr/share/pki/etc/tomcat.conf INFO: Loading instance Tomcat config: /etc/pki/pki-tomcat/tomcat.conf INFO: Loading password config: /etc/pki/pki-tomcat/password.conf INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/ca/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/ca/conf/registry.cfg INFO: Loading subsystem config: /var/lib/pki/pki-tomcat/kra/conf/CS.cfg INFO: Loading subsystem registry: /var/lib/pki/pki-tomcat/kra/conf/registry.cfg INFO: Loading instance registry: /etc/sysconfig/pki/tomcat/pki-tomcat/pki-tomcat DEBUG: - user: pkiuser DEBUG: - group: pkiuser INFO: Backing up keys into /etc/pki/pki-tomcat/alias/kra_backup_keys.p12 DEBUG: Command: pki-server subsystem-cert-export kra -i pki-tomcat --pkcs12-file /etc/pki/pki-tomcat/alias/kra_backup_keys.p12 --pkcs12-password-file /tmp/tmpfncdbqd1/password.txt WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. WARNING: The SHA-1 algorithm used in org.mozilla.jss.pkcs12.SafeBag::getLocalKeyIDFromCert:264 is deprecated. Use a more secure algorithm. DEBUG: Command: systemctl enable pki-tomcatd@pki-tomcat.service INFO: Removing directory /root/.dogtag/pki-tomcat/kra DEBUG: Command: rm -rf /root/.dogtag/pki-tomcat/kra INFO: END spawning KRA subsystem in pki-tomcat instance INFO: Creating /var/log/pki/pki-tomcat/kra/archive/spawn_deployment.cfg.20221218005604 DEBUG: Command: cp -p /etc/sysconfig/pki/tomcat/pki-tomcat/kra/deployment.cfg /var/log/pki/pki-tomcat/kra/archive/spawn_deployment.cfg.20221218005604 DEBUG: Command: chmod 660 /var/log/pki/pki-tomcat/kra/archive/spawn_deployment.cfg.20221218005604 DEBUG: Command: chown 17:17 /var/log/pki/pki-tomcat/kra/archive/spawn_deployment.cfg.20221218005604 INFO: Creating /var/log/pki/pki-tomcat/kra/archive/spawn_manifest.20221218005604 DEBUG: Command: cp -p /etc/sysconfig/pki/tomcat/pki-tomcat/kra/manifest /var/log/pki/pki-tomcat/kra/archive/spawn_manifest.20221218005604 DEBUG: Command: chmod 660 /var/log/pki/pki-tomcat/kra/archive/spawn_manifest.20221218005604 DEBUG: Command: chown 17:17 /var/log/pki/pki-tomcat/kra/archive/spawn_manifest.20221218005604 2022-12-17T23:58:11Z DEBUG completed creating KRA instance 2022-12-17T23:58:11Z DEBUG step duration: pki-tomcatd __spawn_instance 128.25 sec 2022-12-17T23:58:11Z DEBUG [2/9]: create KRA agent 2022-12-17T23:58:11Z DEBUG add_entry_to_group: dn=uid=ipakra,ou=people,o=kra,o=ipaca group_dn=cn=Data Recovery Manager Agents,ou=groups,o=kra,o=ipaca member_attr=uniqueMember 2022-12-17T23:58:11Z DEBUG step duration: pki-tomcatd __create_kra_agent 0.01 sec 2022-12-17T23:58:11Z DEBUG [3/9]: enabling ephemeral requests 2022-12-17T23:58:11Z DEBUG Ensuring that service pki-tomcatd@pki-tomcat is not running while the next set of commands is being executed. 2022-12-17T23:58:11Z DEBUG Starting external process 2022-12-17T23:58:11Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:58:11Z DEBUG Process finished, return code=0 2022-12-17T23:58:11Z DEBUG stdout=active 2022-12-17T23:58:11Z DEBUG stderr= 2022-12-17T23:58:11Z DEBUG Stopping pki-tomcatd@pki-tomcat. 2022-12-17T23:58:11Z DEBUG Starting external process 2022-12-17T23:58:11Z DEBUG args=['/bin/systemctl', 'stop', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:58:12Z DEBUG Process finished, return code=0 2022-12-17T23:58:12Z DEBUG stdout= 2022-12-17T23:58:12Z DEBUG stderr= 2022-12-17T23:58:12Z DEBUG Stop of pki-tomcatd@pki-tomcat.service complete 2022-12-17T23:58:12Z DEBUG Starting pki-tomcatd@pki-tomcat. 2022-12-17T23:58:12Z DEBUG Starting external process 2022-12-17T23:58:12Z DEBUG args=['/bin/systemctl', 'start', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:58:38Z DEBUG Process finished, return code=0 2022-12-17T23:58:38Z DEBUG stdout= 2022-12-17T23:58:38Z DEBUG stderr= 2022-12-17T23:58:38Z DEBUG Starting external process 2022-12-17T23:58:38Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:58:38Z DEBUG Process finished, return code=0 2022-12-17T23:58:38Z DEBUG stdout=active 2022-12-17T23:58:38Z DEBUG stderr= 2022-12-17T23:58:38Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 120 2022-12-17T23:58:38Z DEBUG waiting for port: 8080 2022-12-17T23:58:38Z DEBUG SUCCESS: port: 8080 2022-12-17T23:58:38Z DEBUG waiting for port: 8443 2022-12-17T23:58:38Z DEBUG SUCCESS: port: 8443 2022-12-17T23:58:38Z DEBUG Start of pki-tomcatd@pki-tomcat.service complete 2022-12-17T23:58:38Z DEBUG step duration: pki-tomcatd enable_ephemeral 26.72 sec 2022-12-17T23:58:38Z DEBUG [4/9]: restarting KRA 2022-12-17T23:58:38Z DEBUG Starting external process 2022-12-17T23:58:38Z DEBUG args=['/bin/systemctl', 'restart', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:59:05Z DEBUG Process finished, return code=0 2022-12-17T23:59:05Z DEBUG stdout= 2022-12-17T23:59:05Z DEBUG stderr= 2022-12-17T23:59:05Z DEBUG Starting external process 2022-12-17T23:59:05Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:59:05Z DEBUG Process finished, return code=0 2022-12-17T23:59:05Z DEBUG stdout=active 2022-12-17T23:59:05Z DEBUG stderr= 2022-12-17T23:59:05Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 120 2022-12-17T23:59:05Z DEBUG waiting for port: 8080 2022-12-17T23:59:05Z DEBUG SUCCESS: port: 8080 2022-12-17T23:59:05Z DEBUG waiting for port: 8443 2022-12-17T23:59:05Z DEBUG SUCCESS: port: 8443 2022-12-17T23:59:05Z DEBUG Restart of pki-tomcatd@pki-tomcat.service complete 2022-12-17T23:59:05Z DEBUG step duration: pki-tomcatd restart_instance 26.58 sec 2022-12-17T23:59:05Z DEBUG [5/9]: configure certmonger for renewals 2022-12-17T23:59:05Z DEBUG Starting external process 2022-12-17T23:59:05Z DEBUG args=['/bin/systemctl', 'enable', 'certmonger.service'] 2022-12-17T23:59:05Z DEBUG Process finished, return code=0 2022-12-17T23:59:05Z DEBUG stdout= 2022-12-17T23:59:05Z DEBUG stderr= 2022-12-17T23:59:05Z DEBUG Starting external process 2022-12-17T23:59:05Z DEBUG args=['/bin/systemctl', 'is-active', 'dbus.service'] 2022-12-17T23:59:05Z DEBUG Process finished, return code=0 2022-12-17T23:59:05Z DEBUG stdout=active 2022-12-17T23:59:05Z DEBUG stderr= 2022-12-17T23:59:05Z DEBUG Starting external process 2022-12-17T23:59:05Z DEBUG args=['/bin/systemctl', 'start', 'certmonger.service'] 2022-12-17T23:59:05Z DEBUG Process finished, return code=0 2022-12-17T23:59:05Z DEBUG stdout= 2022-12-17T23:59:05Z DEBUG stderr= 2022-12-17T23:59:05Z DEBUG Starting external process 2022-12-17T23:59:05Z DEBUG args=['/bin/systemctl', 'is-active', 'certmonger.service'] 2022-12-17T23:59:05Z DEBUG Process finished, return code=0 2022-12-17T23:59:05Z DEBUG stdout=active 2022-12-17T23:59:05Z DEBUG stderr= 2022-12-17T23:59:05Z DEBUG Start of certmonger.service complete 2022-12-17T23:59:05Z DEBUG step duration: pki-tomcatd configure_certmonger_renewal_helpers 0.47 sec 2022-12-17T23:59:05Z DEBUG [6/9]: configure certificate renewals 2022-12-17T23:59:05Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:59:06Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:59:08Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:59:09Z DEBUG step duration: pki-tomcatd configure_renewal 4.40 sec 2022-12-17T23:59:09Z DEBUG [7/9]: add vault container 2022-12-17T23:59:09Z DEBUG Starting external process 2022-12-17T23:59:09Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp7unfdcn7', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:59:09Z DEBUG Process finished, return code=0 2022-12-17T23:59:09Z DEBUG stdout=add objectClass: top nsContainer add cn: kra adding new entry "cn=kra,dc=redacted_domain,dc=com" modify complete add objectClass: top ipaVaultContainer add cn: vaults adding new entry "cn=vaults,cn=kra,dc=redacted_domain,dc=com" modify complete add objectClass: top ipaVaultContainer add cn: services adding new entry "cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com" modify complete add objectClass: top ipaVaultContainer add cn: shared adding new entry "cn=shared,cn=vaults,cn=kra,dc=redacted_domain,dc=com" modify complete add objectClass: top ipaVaultContainer add cn: users adding new entry "cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:59:09Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:59:09Z DEBUG step duration: pki-tomcatd __add_vault_container 0.03 sec 2022-12-17T23:59:09Z DEBUG [8/9]: apply LDAP updates 2022-12-17T23:59:09Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:59:09Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:59:09Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:59:09Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:59:09Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:59:09Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:59:09Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:59:09Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:59:09Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:59:10Z DEBUG Created connection context.ldap2_139969598472016 2022-12-17T23:59:10Z DEBUG raw: idrange_show('REDACTED_DOMAIN.COM_id_range', version='2.251') 2022-12-17T23:59:10Z DEBUG idrange_show('REDACTED_DOMAIN.COM_id_range', rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:59:10Z DEBUG flushing ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:59:10Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:59:11Z DEBUG Parsing update file '/usr/share/ipa/updates/40-vault.update' 2022-12-17T23:59:11Z DEBUG Updating existing entry: cn=vaults,cn=kra,dc=redacted_domain,dc=com 2022-12-17T23:59:11Z DEBUG --------------------------------------------- 2022-12-17T23:59:11Z DEBUG Initial value 2022-12-17T23:59:11Z DEBUG dn: cn=vaults,cn=kra,dc=redacted_domain,dc=com 2022-12-17T23:59:11Z DEBUG objectClass: 2022-12-17T23:59:11Z DEBUG top 2022-12-17T23:59:11Z DEBUG ipaVaultContainer 2022-12-17T23:59:11Z DEBUG cn: 2022-12-17T23:59:11Z DEBUG vaults 2022-12-17T23:59:11Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value [] 2022-12-17T23:59:11Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:59:11Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)' from aci, current value [] 2022-12-17T23:59:11Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com";)' not in aci 2022-12-17T23:59:11Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' from aci, current value [] 2022-12-17T23:59:11Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' not in aci 2022-12-17T23:59:11Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' from aci, current value [] 2022-12-17T23:59:11Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' not in aci 2022-12-17T23:59:11Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' from aci, current value [] 2022-12-17T23:59:11Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' not in aci 2022-12-17T23:59:11Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' from aci, current value [] 2022-12-17T23:59:11Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' not in aci 2022-12-17T23:59:11Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' from aci, current value [] 2022-12-17T23:59:11Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' not in aci 2022-12-17T23:59:11Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' from aci, current value [] 2022-12-17T23:59:11Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' not in aci 2022-12-17T23:59:11Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)' from aci, current value [] 2022-12-17T23:59:11Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@REDACTED_DOMAIN.COM,cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)' not in aci 2022-12-17T23:59:11Z DEBUG addifexist: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)' to aci, current value [] 2022-12-17T23:59:11Z DEBUG addifexist: set aci to ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)' to aci, current value ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: set aci to ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: set aci to ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: set aci to ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: set aci to ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: set aci to ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)' to aci, current value ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: set aci to ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)' to aci, current value ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: set aci to ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: set aci to ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: set aci to ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' to aci, current value ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: set aci to ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' to aci, current value ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: set aci to ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Vault owners can manage the vault"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: set aci to ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Vault owners can manage the vault"; allow(write, delete) userattr="owner#USERDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Vault owners can manage the vault"; allow(write, delete) userattr="owner#USERDN";)'] 2022-12-17T23:59:11Z DEBUG addifexist: set aci to ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Vault owners can manage the vault"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(write, delete) userattr="owner#GROUPDN";)'] 2022-12-17T23:59:11Z DEBUG --------------------------------------------- 2022-12-17T23:59:11Z DEBUG Final value after applying updates 2022-12-17T23:59:11Z DEBUG dn: cn=vaults,cn=kra,dc=redacted_domain,dc=com 2022-12-17T23:59:11Z DEBUG objectClass: 2022-12-17T23:59:11Z DEBUG top 2022-12-17T23:59:11Z DEBUG ipaVaultContainer 2022-12-17T23:59:11Z DEBUG cn: 2022-12-17T23:59:11Z DEBUG vaults 2022-12-17T23:59:11Z DEBUG aci: 2022-12-17T23:59:11Z DEBUG (target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";) 2022-12-17T23:59:11Z DEBUG (target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";) 2022-12-17T23:59:11Z DEBUG (targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";) 2022-12-17T23:59:11Z DEBUG (targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";) 2022-12-17T23:59:11Z DEBUG (targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";) 2022-12-17T23:59:11Z DEBUG (targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";) 2022-12-17T23:59:11Z DEBUG (targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";) 2022-12-17T23:59:11Z DEBUG (targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";) 2022-12-17T23:59:11Z DEBUG (targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";) 2022-12-17T23:59:11Z DEBUG (targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";) 2022-12-17T23:59:11Z DEBUG (targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";) 2022-12-17T23:59:11Z DEBUG (targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";) 2022-12-17T23:59:11Z DEBUG (targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Vault owners can manage the vault"; allow(write, delete) userattr="owner#USERDN";) 2022-12-17T23:59:11Z DEBUG (targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(write, delete) userattr="owner#GROUPDN";) 2022-12-17T23:59:11Z DEBUG [(2, 'aci', ['(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Vault owners can manage the vault"; allow(write, delete) userattr="owner#USERDN";)', '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(write, delete) userattr="owner#GROUPDN";)'])] 2022-12-17T23:59:11Z DEBUG Updated 1 2022-12-17T23:59:11Z DEBUG update_entry modlist [(2, 'aci', [b'(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', b'(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=redacted_domain,dc=com")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=redacted_domain,dc=com" and userattr="owner#SELFDN";)', b'(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)', b'(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)', b'(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)', b'(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)', b'(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)', b'(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)', b'(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)', b'(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)', b'(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)', b'(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)', b'(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Vault owners can manage the vault"; allow(write, delete) userattr="owner#USERDN";)', b'(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(write, delete) userattr="owner#GROUPDN";)'])] 2022-12-17T23:59:11Z DEBUG Done 2022-12-17T23:59:11Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-vault.update 0.014 sec 2022-12-17T23:59:11Z DEBUG Destroyed connection context.ldap2_139969598472016 2022-12-17T23:59:11Z DEBUG step duration: pki-tomcatd __apply_updates 1.12 sec 2022-12-17T23:59:11Z DEBUG [9/9]: enabling KRA instance 2022-12-17T23:59:11Z DEBUG Starting external process 2022-12-17T23:59:11Z DEBUG args=['/bin/systemctl', 'unmask', 'pki-tomcatd.target'] 2022-12-17T23:59:11Z DEBUG Process finished, return code=0 2022-12-17T23:59:11Z DEBUG stdout= 2022-12-17T23:59:11Z DEBUG stderr= 2022-12-17T23:59:11Z DEBUG Starting external process 2022-12-17T23:59:11Z DEBUG args=['/bin/systemctl', 'disable', 'pki-tomcatd.target'] 2022-12-17T23:59:11Z DEBUG Process finished, return code=0 2022-12-17T23:59:11Z DEBUG stdout= 2022-12-17T23:59:11Z DEBUG stderr= 2022-12-17T23:59:11Z DEBUG step duration: pki-tomcatd __enable_instance 0.82 sec 2022-12-17T23:59:11Z DEBUG Done configuring KRA server (pki-tomcatd). 2022-12-17T23:59:11Z DEBUG service duration: pki-tomcatd 188.41 sec 2022-12-17T23:59:11Z DEBUG Removing /var/lib/ipa/tmp-dvglda_f 2022-12-17T23:59:11Z DEBUG Removing /root/.dogtag/pki-tomcat/kra 2022-12-17T23:59:11Z DEBUG Restarting the directory server 2022-12-17T23:59:11Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:59:11Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:59:11Z DEBUG Destroyed connection context.ldap2_139969608432400 2022-12-17T23:59:11Z DEBUG Starting external process 2022-12-17T23:59:11Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:59:17Z DEBUG Process finished, return code=0 2022-12-17T23:59:17Z DEBUG stdout= 2022-12-17T23:59:17Z DEBUG stderr= 2022-12-17T23:59:17Z DEBUG Starting external process 2022-12-17T23:59:17Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:59:17Z DEBUG Process finished, return code=0 2022-12-17T23:59:17Z DEBUG stdout=active 2022-12-17T23:59:17Z DEBUG stderr= 2022-12-17T23:59:17Z DEBUG wait_for_open_ports: localhost [389] timeout 120 2022-12-17T23:59:17Z DEBUG waiting for port: 389 2022-12-17T23:59:17Z DEBUG SUCCESS: port: 389 2022-12-17T23:59:17Z DEBUG Restart of dirsrv@REDACTED_DOMAIN-COM.service complete 2022-12-17T23:59:17Z DEBUG Starting external process 2022-12-17T23:59:17Z DEBUG args=['/bin/systemctl', 'is-active', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-17T23:59:17Z DEBUG Process finished, return code=0 2022-12-17T23:59:17Z DEBUG stdout=active 2022-12-17T23:59:17Z DEBUG stderr= 2022-12-17T23:59:17Z DEBUG Created connection context.ldap2_139969608432400 2022-12-17T23:59:17Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:59:17Z DEBUG Ensuring that service pki-tomcatd@pki-tomcat is not running while the next set of commands is being executed. 2022-12-17T23:59:17Z DEBUG Starting external process 2022-12-17T23:59:17Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:59:17Z DEBUG Process finished, return code=0 2022-12-17T23:59:17Z DEBUG stdout=active 2022-12-17T23:59:17Z DEBUG stderr= 2022-12-17T23:59:17Z DEBUG Stopping pki-tomcatd@pki-tomcat. 2022-12-17T23:59:17Z DEBUG Starting external process 2022-12-17T23:59:17Z DEBUG args=['/bin/systemctl', 'stop', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:59:18Z DEBUG Process finished, return code=0 2022-12-17T23:59:18Z DEBUG stdout= 2022-12-17T23:59:18Z DEBUG stderr= 2022-12-17T23:59:18Z DEBUG Stop of pki-tomcatd@pki-tomcat.service complete 2022-12-17T23:59:18Z DEBUG Starting pki-tomcatd@pki-tomcat. 2022-12-17T23:59:18Z DEBUG Starting external process 2022-12-17T23:59:18Z DEBUG args=['/bin/systemctl', 'start', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:59:46Z DEBUG Process finished, return code=0 2022-12-17T23:59:46Z DEBUG stdout= 2022-12-17T23:59:46Z DEBUG stderr= 2022-12-17T23:59:46Z DEBUG Starting external process 2022-12-17T23:59:46Z DEBUG args=['/bin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2022-12-17T23:59:46Z DEBUG Process finished, return code=0 2022-12-17T23:59:46Z DEBUG stdout=active 2022-12-17T23:59:46Z DEBUG stderr= 2022-12-17T23:59:46Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 120 2022-12-17T23:59:46Z DEBUG waiting for port: 8080 2022-12-17T23:59:46Z DEBUG SUCCESS: port: 8080 2022-12-17T23:59:46Z DEBUG waiting for port: 8443 2022-12-17T23:59:46Z DEBUG SUCCESS: port: 8443 2022-12-17T23:59:46Z DEBUG Start of pki-tomcatd@pki-tomcat.service complete 2022-12-17T23:59:46Z DEBUG Starting external process 2022-12-17T23:59:46Z DEBUG args=['/bin/systemctl', 'restart', 'httpd.service'] 2022-12-17T23:59:49Z DEBUG Process finished, return code=0 2022-12-17T23:59:49Z DEBUG stdout= 2022-12-17T23:59:49Z DEBUG stderr= 2022-12-17T23:59:49Z DEBUG Starting external process 2022-12-17T23:59:49Z DEBUG args=['/bin/systemctl', 'is-active', 'httpd.service'] 2022-12-17T23:59:49Z DEBUG Process finished, return code=0 2022-12-17T23:59:49Z DEBUG stdout=active 2022-12-17T23:59:49Z DEBUG stderr= 2022-12-17T23:59:49Z DEBUG Restart of httpd.service complete 2022-12-17T23:59:49Z DEBUG Starting external process 2022-12-17T23:59:49Z DEBUG args=['/bin/systemctl', 'is-active', 'named.service'] 2022-12-17T23:59:49Z DEBUG Process finished, return code=3 2022-12-17T23:59:49Z DEBUG stdout=inactive 2022-12-17T23:59:49Z DEBUG stderr= 2022-12-17T23:59:51Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:59:51Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-17T23:59:51Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-17T23:59:51Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-17T23:59:51Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-17T23:59:51Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-17T23:59:51Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-17T23:59:51Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-17T23:59:51Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-17T23:59:51Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-17T23:59:52Z DEBUG Created connection context.ldap2_140515196074960 2022-12-17T23:59:52Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-17T23:59:52Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:59:52Z INFO dnssec-validation yes 2022-12-17T23:59:52Z DEBUG Starting external process 2022-12-17T23:59:52Z DEBUG args=['/bin/systemctl', 'stop', 'named.service'] 2022-12-17T23:59:52Z DEBUG Process finished, return code=0 2022-12-17T23:59:52Z DEBUG stdout= 2022-12-17T23:59:52Z DEBUG stderr= 2022-12-17T23:59:52Z DEBUG Stop of named.service complete 2022-12-17T23:59:52Z DEBUG raw: dnszone_show('redacted_domain.com', version='2.251') 2022-12-17T23:59:52Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:59:52Z DEBUG Configuring DNS (named) 2022-12-17T23:59:52Z DEBUG [1/12]: generating rndc key file 2022-12-17T23:59:52Z DEBUG Starting external process 2022-12-17T23:59:52Z DEBUG args=['/usr/libexec/generate-rndc-key.sh'] 2022-12-17T23:59:52Z DEBUG Process finished, return code=0 2022-12-17T23:59:52Z DEBUG stdout=Generating /etc/rndc.key: OK 2022-12-17T23:59:52Z DEBUG stderr= 2022-12-17T23:59:52Z DEBUG step duration: named __generate_rndc_key 0.09 sec 2022-12-17T23:59:52Z DEBUG [2/12]: adding DNS container 2022-12-17T23:59:52Z DEBUG Starting external process 2022-12-17T23:59:52Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpzssfk9wu', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-17T23:59:52Z DEBUG Process finished, return code=0 2022-12-17T23:59:52Z DEBUG stdout=add objectClass: idnsConfigObject nsContainer ipaConfigObject ipaDNSContainer top add cn: dns add ipaConfigString: DNSVersion 1 add ipaDNSVersion: 2 add aci: (targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";) (target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) (target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=redacted_domain,dc=com")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) (targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=redacted_domain,dc=com";) adding new entry "cn=dns,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: servers adding new entry "cn=servers,cn=dns,dc=redacted_domain,dc=com" modify complete 2022-12-17T23:59:52Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-17T23:59:52Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-17T23:59:52Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-17T23:59:53Z DEBUG step duration: named __setup_dns_container 1.23 sec 2022-12-17T23:59:53Z DEBUG [3/12]: setting up our zone 2022-12-17T23:59:53Z DEBUG raw: dnszone_add('redacted_domain.com.', idnssoamname='master.redacted_domain.com.', idnssoarname='hostmaster.redacted_domain.com.', idnsupdatepolicy='grant REDACTED_DOMAIN.COM krb5-self * A; grant REDACTED_DOMAIN.COM krb5-self * AAAA; grant REDACTED_DOMAIN.COM krb5-self * SSHFP;', idnsallowdynupdate=True, idnsallowquery='any', idnsallowtransfer='none', skip_overlap_check=True, force=True, version='2.251') 2022-12-17T23:59:53Z DEBUG dnszone_add(, idnssoamname=, idnssoarname=, idnssoarefresh=3600, idnssoaretry=900, idnssoaexpire=1209600, idnssoaminimum=3600, idnsupdatepolicy='grant REDACTED_DOMAIN.COM krb5-self * A; grant REDACTED_DOMAIN.COM krb5-self * AAAA; grant REDACTED_DOMAIN.COM krb5-self * SSHFP;', idnsallowdynupdate=True, idnsallowquery='any;', idnsallowtransfer='none;', skip_overlap_check=True, force=True, skip_nameserver_check=False, all=False, raw=False, version='2.251') 2022-12-17T23:59:53Z DEBUG raw: dnsrecord_add('redacted_domain.com', '_kerberos', txtrecord='REDACTED_DOMAIN.COM', version='2.251') 2022-12-17T23:59:53Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, txtrecord=('REDACTED_DOMAIN.COM',), force=False, structured=False, all=False, raw=False, version='2.251') 2022-12-17T23:59:53Z DEBUG step duration: named __setup_zone 0.04 sec 2022-12-17T23:59:53Z DEBUG [4/12]: setting up our own record 2022-12-17T23:59:53Z DEBUG raw: dnszone_show('redacted_domain.com', version='2.251') 2022-12-17T23:59:53Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:59:53Z DEBUG raw: dnsrecord_add('redacted_domain.com', 'master', arecord='172.16.0.21', version='2.251') 2022-12-17T23:59:53Z DEBUG dnsrecord_add(, , arecord=('172.16.0.21',), a_extra_create_reverse=False, aaaa_extra_create_reverse=False, force=False, structured=False, all=False, raw=False, version='2.251') 2022-12-17T23:59:53Z DEBUG raw: dnszone_show('21.0.16.172.in-addr.arpa.', version='2.251') 2022-12-17T23:59:53Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:59:53Z DEBUG raw: dnszone_show('0.16.172.in-addr.arpa.', version='2.251') 2022-12-17T23:59:53Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:59:53Z DEBUG raw: dnszone_show('16.172.in-addr.arpa.', version='2.251') 2022-12-17T23:59:53Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:59:53Z DEBUG raw: dnszone_show('172.in-addr.arpa.', version='2.251') 2022-12-17T23:59:53Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:59:53Z DEBUG raw: dnszone_show('in-addr.arpa.', version='2.251') 2022-12-17T23:59:53Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:59:53Z DEBUG raw: dnszone_show('arpa.', version='2.251') 2022-12-17T23:59:53Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.251') 2022-12-17T23:59:53Z DEBUG step duration: named __add_self 0.03 sec 2022-12-17T23:59:53Z DEBUG [5/12]: setting up records for other masters 2022-12-17T23:59:53Z DEBUG step duration: named __add_others 0.00 sec 2022-12-17T23:59:53Z DEBUG [6/12]: adding NS record to the zones 2022-12-17T23:59:53Z DEBUG raw: dnszone_find(None, version='2.251') 2022-12-17T23:59:53Z DEBUG dnszone_find(None, forward_only=False, all=False, raw=False, version='2.251', pkey_only=False) 2022-12-17T23:59:53Z DEBUG adding self NS to zone redacted_domain.com. apex 2022-12-17T23:59:53Z DEBUG raw: dnsrecord_add('redacted_domain.com.', '@', nsrecord='master.redacted_domain.com.', force=True, version='2.251') 2022-12-17T23:59:53Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, nsrecord=('master.redacted_domain.com.',), force=True, structured=False, all=False, raw=False, version='2.251') 2022-12-17T23:59:53Z DEBUG update_entry modlist [(2, 'nsrecord', [b'master.redacted_domain.com.'])] 2022-12-17T23:59:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:59:53Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:59:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:59:53Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-17T23:59:53Z DEBUG step duration: named __add_self_ns 0.03 sec 2022-12-17T23:59:53Z DEBUG [7/12]: setting up kerberos principal 2022-12-17T23:59:53Z DEBUG Starting external process 2022-12-17T23:59:53Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey DNS/master.redacted_domain.com@REDACTED_DOMAIN.COM', '-x', 'ipa-setup-override-restrictions'] 2022-12-17T23:59:54Z DEBUG Process finished, return code=0 2022-12-17T23:59:54Z DEBUG stdout=Authenticating as principal root/admin@REDACTED_DOMAIN.COM with password. Principal "DNS/master.redacted_domain.com@REDACTED_DOMAIN.COM" created. 2022-12-17T23:59:54Z DEBUG stderr=No policy specified for DNS/master.redacted_domain.com@REDACTED_DOMAIN.COM; defaulting to no policy 2022-12-17T23:59:54Z DEBUG Backing up system configuration file '/etc/named.keytab' 2022-12-17T23:59:54Z DEBUG -> Not backing up - '/etc/named.keytab' doesn't exist 2022-12-17T23:59:54Z DEBUG Starting external process 2022-12-17T23:59:54Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/named.keytab DNS/master.redacted_domain.com@REDACTED_DOMAIN.COM', '-x', 'ipa-setup-override-restrictions'] 2022-12-17T23:59:54Z DEBUG Process finished, return code=0 2022-12-17T23:59:54Z DEBUG stdout=Authenticating as principal root/admin@REDACTED_DOMAIN.COM with password. Entry for principal DNS/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/named.keytab. Entry for principal DNS/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/named.keytab. 2022-12-17T23:59:54Z DEBUG stderr= 2022-12-17T23:59:54Z DEBUG step duration: named __setup_principal 0.39 sec 2022-12-17T23:59:54Z DEBUG [8/12]: setting up LDAPI autobind 2022-12-17T23:59:54Z DEBUG Created autobind entry cn=named,cn=auto_bind,cn=config 2022-12-17T23:59:54Z DEBUG Creating reload task cn=reload_1671321594,cn=reload ldapi mappings,cn=tasks,cn=config 2022-12-18T00:00:06Z DEBUG Task cn=reload_1671321594,cn=reload ldapi mappings,cn=tasks,cn=config has finished with exit code 0 2022-12-18T00:00:06Z DEBUG step duration: named setup_autobind 12.14 sec 2022-12-18T00:00:06Z DEBUG [9/12]: setting up named.conf 2022-12-18T00:00:06Z DEBUG Backing up system configuration file '/etc/named.conf' 2022-12-18T00:00:06Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-18T00:00:06Z INFO created new /etc/named.conf 2022-12-18T00:00:06Z INFO created named user config '/etc/named/ipa-ext.conf' 2022-12-18T00:00:06Z INFO created named user config '/etc/named/ipa-options-ext.conf' 2022-12-18T00:00:06Z INFO created named user config '/etc/named/ipa-logging-ext.conf' 2022-12-18T00:00:06Z DEBUG step duration: named setup_named_conf 0.00 sec 2022-12-18T00:00:06Z DEBUG [10/12]: setting up server configuration 2022-12-18T00:00:06Z DEBUG cn=servers,cn=dns container already exists 2022-12-18T00:00:06Z DEBUG raw: dnsserver_add('master.redacted_domain.com', idnssoamname=, version='2.251') 2022-12-18T00:00:06Z DEBUG dnsserver_add('master.redacted_domain.com', idnssoamname=, all=False, raw=False, version='2.251') 2022-12-18T00:00:06Z DEBUG raw: dnsserver_mod('master.redacted_domain.com', idnsforwarders=['172.16.16.172'], idnsforwardpolicy='first', version='2.251') 2022-12-18T00:00:06Z DEBUG dnsserver_mod('master.redacted_domain.com', idnsforwarders=('172.16.16.172',), idnsforwardpolicy='first', rights=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:06Z DEBUG update_entry modlist [(2, 'idnsforwardpolicy', [b'first']), (2, 'idnsforwarders', [b'172.16.16.172'])] 2022-12-18T00:00:06Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-18T00:00:06Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-18T00:00:06Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2022-12-18T00:00:06Z DEBUG step duration: named __setup_server_configuration 0.02 sec 2022-12-18T00:00:06Z DEBUG [11/12]: configuring named to start on boot 2022-12-18T00:00:06Z DEBUG Starting external process 2022-12-18T00:00:06Z DEBUG args=['/bin/systemctl', 'stop', 'named-pkcs11.service'] 2022-12-18T00:00:06Z DEBUG Process finished, return code=5 2022-12-18T00:00:06Z DEBUG stdout= 2022-12-18T00:00:06Z DEBUG stderr=Failed to stop named-pkcs11.service: Unit named-pkcs11.service not loaded. 2022-12-18T00:00:06Z DEBUG Unable to stop named-pkcs11.service (CalledProcessError(Command ['/bin/systemctl', 'stop', 'named-pkcs11.service'] returned non-zero exit status 5: 'Failed to stop named-pkcs11.service: Unit named-pkcs11.service not loaded.\n')) 2022-12-18T00:00:06Z DEBUG Starting external process 2022-12-18T00:00:06Z DEBUG args=['/bin/systemctl', 'mask', 'named-pkcs11.service'] 2022-12-18T00:00:06Z DEBUG Process finished, return code=0 2022-12-18T00:00:06Z DEBUG stdout= 2022-12-18T00:00:06Z DEBUG stderr=Unit named-pkcs11.service does not exist, proceeding anyway. Created symlink /etc/systemd/system/named-pkcs11.service → /dev/null. 2022-12-18T00:00:06Z DEBUG Starting external process 2022-12-18T00:00:06Z DEBUG args=['/bin/systemctl', 'unmask', 'named.service'] 2022-12-18T00:00:07Z DEBUG Process finished, return code=0 2022-12-18T00:00:07Z DEBUG stdout= 2022-12-18T00:00:07Z DEBUG stderr= 2022-12-18T00:00:07Z DEBUG Starting external process 2022-12-18T00:00:07Z DEBUG args=['/bin/systemctl', 'disable', 'named.service'] 2022-12-18T00:00:07Z DEBUG Process finished, return code=0 2022-12-18T00:00:07Z DEBUG stdout= 2022-12-18T00:00:07Z DEBUG stderr= 2022-12-18T00:00:07Z DEBUG step duration: named switch_service 1.25 sec 2022-12-18T00:00:07Z DEBUG [12/12]: changing resolv.conf to point to ourselves 2022-12-18T00:00:07Z DEBUG Starting external process 2022-12-18T00:00:07Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-18T00:00:07Z DEBUG Process finished, return code=0 2022-12-18T00:00:07Z DEBUG stdout= 2022-12-18T00:00:07Z DEBUG stderr= 2022-12-18T00:00:07Z DEBUG Starting external process 2022-12-18T00:00:07Z DEBUG args=['/sbin/restorecon', '-F', '/etc/systemd/resolved.conf.d'] 2022-12-18T00:00:07Z DEBUG Process finished, return code=0 2022-12-18T00:00:07Z DEBUG stdout= 2022-12-18T00:00:07Z DEBUG stderr= 2022-12-18T00:00:07Z DEBUG Starting external process 2022-12-18T00:00:07Z DEBUG args=['/usr/sbin/selinuxenabled'] 2022-12-18T00:00:07Z DEBUG Process finished, return code=0 2022-12-18T00:00:07Z DEBUG stdout= 2022-12-18T00:00:07Z DEBUG stderr= 2022-12-18T00:00:07Z DEBUG Starting external process 2022-12-18T00:00:07Z DEBUG args=['/sbin/restorecon', '-F', '/etc/systemd/resolved.conf.d/zzz-ipa.conf'] 2022-12-18T00:00:07Z DEBUG Process finished, return code=0 2022-12-18T00:00:07Z DEBUG stdout= 2022-12-18T00:00:07Z DEBUG stderr= 2022-12-18T00:00:07Z DEBUG Starting external process 2022-12-18T00:00:07Z DEBUG args=['/bin/systemctl', 'reload-or-restart', 'systemd-resolved.service'] 2022-12-18T00:00:07Z DEBUG Process finished, return code=0 2022-12-18T00:00:07Z DEBUG stdout= 2022-12-18T00:00:07Z DEBUG stderr= 2022-12-18T00:00:07Z DEBUG Starting external process 2022-12-18T00:00:07Z DEBUG args=['/bin/systemctl', 'is-active', 'systemd-resolved.service'] 2022-12-18T00:00:07Z DEBUG Process finished, return code=0 2022-12-18T00:00:07Z DEBUG stdout=active 2022-12-18T00:00:07Z DEBUG stderr= 2022-12-18T00:00:07Z DEBUG Restart of systemd-resolved.service complete 2022-12-18T00:00:07Z DEBUG Backing up system configuration file '/etc/resolv.conf' 2022-12-18T00:00:07Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-18T00:00:07Z DEBUG Starting external process 2022-12-18T00:00:07Z DEBUG args=['/bin/systemctl', 'is-enabled', 'NetworkManager.service'] 2022-12-18T00:00:07Z DEBUG Process finished, return code=0 2022-12-18T00:00:07Z DEBUG stdout=enabled 2022-12-18T00:00:07Z DEBUG stderr= 2022-12-18T00:00:07Z DEBUG Network Manager is enabled, write /etc/NetworkManager/conf.d/zzz-ipa.conf 2022-12-18T00:00:07Z DEBUG Starting external process 2022-12-18T00:00:07Z DEBUG args=['/bin/systemctl', 'reload-or-restart', 'NetworkManager.service'] 2022-12-18T00:00:07Z DEBUG Process finished, return code=0 2022-12-18T00:00:07Z DEBUG stdout= 2022-12-18T00:00:07Z DEBUG stderr= 2022-12-18T00:00:07Z DEBUG Starting external process 2022-12-18T00:00:07Z DEBUG args=['/bin/systemctl', 'is-active', 'NetworkManager.service'] 2022-12-18T00:00:07Z DEBUG Process finished, return code=0 2022-12-18T00:00:07Z DEBUG stdout=active 2022-12-18T00:00:07Z DEBUG stderr= 2022-12-18T00:00:07Z DEBUG Restart of NetworkManager.service complete 2022-12-18T00:00:07Z DEBUG step duration: named setup_resolv_conf 0.26 sec 2022-12-18T00:00:07Z DEBUG Done configuring DNS (named). 2022-12-18T00:00:07Z DEBUG service duration: named 15.49 sec 2022-12-18T00:00:07Z DEBUG Starting external process 2022-12-18T00:00:07Z DEBUG args=['/bin/systemctl', 'restart', 'httpd.service'] 2022-12-18T00:00:10Z DEBUG Process finished, return code=0 2022-12-18T00:00:10Z DEBUG stdout= 2022-12-18T00:00:10Z DEBUG stderr= 2022-12-18T00:00:10Z DEBUG Starting external process 2022-12-18T00:00:10Z DEBUG args=['/bin/systemctl', 'is-active', 'httpd.service'] 2022-12-18T00:00:10Z DEBUG Process finished, return code=0 2022-12-18T00:00:10Z DEBUG stdout=active 2022-12-18T00:00:10Z DEBUG stderr= 2022-12-18T00:00:10Z DEBUG Restart of httpd.service complete 2022-12-18T00:00:10Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-18T00:00:10Z DEBUG Starting external process 2022-12-18T00:00:10Z DEBUG args=['/bin/systemctl', 'stop', 'ipa-dnskeysyncd.service'] 2022-12-18T00:00:10Z DEBUG Process finished, return code=0 2022-12-18T00:00:10Z DEBUG stdout= 2022-12-18T00:00:10Z DEBUG stderr= 2022-12-18T00:00:10Z DEBUG Stop of ipa-dnskeysyncd.service complete 2022-12-18T00:00:10Z DEBUG Configuring DNS key synchronization service (ipa-dnskeysyncd) 2022-12-18T00:00:10Z DEBUG [1/7]: checking status 2022-12-18T00:00:10Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-18T00:00:10Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-18T00:00:10Z DEBUG step duration: ipa-dnskeysyncd __check_dnssec_status 0.00 sec 2022-12-18T00:00:10Z DEBUG [2/7]: setting up bind-dyndb-ldap working directory 2022-12-18T00:00:10Z DEBUG step duration: ipa-dnskeysyncd set_dyndb_ldap_workdir_permissions 0.00 sec 2022-12-18T00:00:10Z DEBUG [3/7]: setting up kerberos principal 2022-12-18T00:00:10Z DEBUG Removing service keytab: /etc/ipa/dnssec/ipa-dnskeysyncd.keytab 2022-12-18T00:00:10Z DEBUG Starting external process 2022-12-18T00:00:10Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey ipa-dnskeysyncd/master.redacted_domain.com@REDACTED_DOMAIN.COM', '-x', 'ipa-setup-override-restrictions'] 2022-12-18T00:00:10Z DEBUG Process finished, return code=0 2022-12-18T00:00:10Z DEBUG stdout=Authenticating as principal root/admin@REDACTED_DOMAIN.COM with password. Principal "ipa-dnskeysyncd/master.redacted_domain.com@REDACTED_DOMAIN.COM" created. 2022-12-18T00:00:10Z DEBUG stderr=No policy specified for ipa-dnskeysyncd/master.redacted_domain.com@REDACTED_DOMAIN.COM; defaulting to no policy 2022-12-18T00:00:10Z DEBUG Starting external process 2022-12-18T00:00:10Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/ipa/dnssec/ipa-dnskeysyncd.keytab ipa-dnskeysyncd/master.redacted_domain.com@REDACTED_DOMAIN.COM', '-x', 'ipa-setup-override-restrictions'] 2022-12-18T00:00:10Z DEBUG Process finished, return code=0 2022-12-18T00:00:10Z DEBUG stdout=Authenticating as principal root/admin@REDACTED_DOMAIN.COM with password. Entry for principal ipa-dnskeysyncd/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. Entry for principal ipa-dnskeysyncd/master.redacted_domain.com@REDACTED_DOMAIN.COM with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/ipa/dnssec/ipa-dnskeysyncd.keytab. 2022-12-18T00:00:10Z DEBUG stderr= 2022-12-18T00:00:10Z DEBUG step duration: ipa-dnskeysyncd __setup_principal 0.42 sec 2022-12-18T00:00:10Z DEBUG [4/7]: setting up SoftHSM 2022-12-18T00:00:10Z DEBUG Creating /var/lib/ipa/dnssec directory 2022-12-18T00:00:10Z DEBUG Creating new softhsm config file 2022-12-18T00:00:10Z DEBUG Setup OpenSSL config for BIND 2022-12-18T00:00:10Z DEBUG Setup BIND sysconfig 2022-12-18T00:00:10Z DEBUG Backing up system configuration file '/etc/sysconfig/named' 2022-12-18T00:00:10Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-18T00:00:10Z DEBUG Setup ipa-dnskeysyncd sysconfig 2022-12-18T00:00:10Z DEBUG Creating tokens /var/lib/ipa/dnssec/tokens directory 2022-12-18T00:00:10Z DEBUG Saving user PIN to /var/lib/ipa/dnssec/softhsm_pin 2022-12-18T00:00:10Z DEBUG Saving SO PIN to /etc/ipa/dnssec/softhsm_pin_so 2022-12-18T00:00:10Z DEBUG Initializing tokens 2022-12-18T00:00:10Z DEBUG Starting external process 2022-12-18T00:00:10Z DEBUG args=['/usr/bin/softhsm2-util', '--init-token', '--free', '--label', 'ipaDNSSEC', '--pin', XXXXXXXX, '--so-pin', XXXXXXXX] 2022-12-18T00:00:10Z DEBUG Process finished, return code=0 2022-12-18T00:00:10Z DEBUG stdout=Slot 0 has a free/uninitialized token. The token has been initialized and is reassigned to slot 1847160237 2022-12-18T00:00:10Z DEBUG stderr= 2022-12-18T00:00:10Z DEBUG step duration: ipa-dnskeysyncd __setup_softhsm 0.04 sec 2022-12-18T00:00:10Z DEBUG [5/7]: adding DNSSEC containers 2022-12-18T00:00:10Z DEBUG Starting external process 2022-12-18T00:00:10Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmp72as1c55', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-18T00:00:10Z DEBUG Process finished, return code=0 2022-12-18T00:00:10Z DEBUG stdout=add objectClass: nsContainer top add cn: sec adding new entry "cn=sec,cn=dns,dc=redacted_domain,dc=com" modify complete add objectClass: nsContainer top add cn: keys adding new entry "cn=keys,cn=sec,cn=dns,dc=redacted_domain,dc=com" modify complete 2022-12-18T00:00:10Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-18T00:00:10Z DEBUG step duration: ipa-dnskeysyncd __setup_dnssec_containers 0.02 sec 2022-12-18T00:00:10Z DEBUG [6/7]: creating replica keys 2022-12-18T00:00:10Z DEBUG Creating replica's key pair 2022-12-18T00:00:11Z DEBUG Storing replica public key to LDAP, ipk11UniqueId=autogenerate,cn=keys,cn=sec,cn=dns,dc=redacted_domain,dc=com 2022-12-18T00:00:11Z DEBUG Replica public key stored 2022-12-18T00:00:11Z DEBUG Setting CKA_WRAP=False for old replica keys 2022-12-18T00:00:11Z DEBUG Changing ownership of token files 2022-12-18T00:00:11Z DEBUG step duration: ipa-dnskeysyncd __setup_replica_keys 1.05 sec 2022-12-18T00:00:11Z DEBUG [7/7]: configuring ipa-dnskeysyncd to start on boot 2022-12-18T00:00:11Z DEBUG Starting external process 2022-12-18T00:00:11Z DEBUG args=['/bin/systemctl', 'unmask', 'ipa-dnskeysyncd.service'] 2022-12-18T00:00:12Z DEBUG Process finished, return code=0 2022-12-18T00:00:12Z DEBUG stdout= 2022-12-18T00:00:12Z DEBUG stderr= 2022-12-18T00:00:12Z DEBUG Starting external process 2022-12-18T00:00:12Z DEBUG args=['/bin/systemctl', 'disable', 'ipa-dnskeysyncd.service'] 2022-12-18T00:00:12Z DEBUG Process finished, return code=0 2022-12-18T00:00:12Z DEBUG stdout= 2022-12-18T00:00:12Z DEBUG stderr= 2022-12-18T00:00:12Z DEBUG step duration: ipa-dnskeysyncd __enable 0.92 sec 2022-12-18T00:00:12Z DEBUG Done configuring DNS key synchronization service (ipa-dnskeysyncd). 2022-12-18T00:00:12Z DEBUG service duration: ipa-dnskeysyncd 2.45 sec 2022-12-18T00:00:12Z DEBUG Starting external process 2022-12-18T00:00:12Z DEBUG args=['/bin/systemctl', 'restart', 'ipa-dnskeysyncd.service'] 2022-12-18T00:00:12Z DEBUG Process finished, return code=0 2022-12-18T00:00:12Z DEBUG stdout= 2022-12-18T00:00:12Z DEBUG stderr= 2022-12-18T00:00:12Z DEBUG Starting external process 2022-12-18T00:00:12Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa-dnskeysyncd.service'] 2022-12-18T00:00:12Z DEBUG Process finished, return code=0 2022-12-18T00:00:12Z DEBUG stdout=active 2022-12-18T00:00:12Z DEBUG stderr= 2022-12-18T00:00:12Z DEBUG Restart of ipa-dnskeysyncd.service complete 2022-12-18T00:00:12Z DEBUG Restarting named 2022-12-18T00:00:12Z DEBUG Starting external process 2022-12-18T00:00:12Z DEBUG args=['/bin/systemctl', 'restart', 'named.service'] 2022-12-18T00:00:12Z DEBUG Process finished, return code=0 2022-12-18T00:00:12Z DEBUG stdout= 2022-12-18T00:00:12Z DEBUG stderr= 2022-12-18T00:00:12Z DEBUG Starting external process 2022-12-18T00:00:12Z DEBUG args=['/bin/systemctl', 'is-active', 'named.service'] 2022-12-18T00:00:12Z DEBUG Process finished, return code=0 2022-12-18T00:00:12Z DEBUG stdout=active 2022-12-18T00:00:12Z DEBUG stderr= 2022-12-18T00:00:12Z DEBUG Restart of named.service complete 2022-12-18T00:00:12Z DEBUG Updating DNS system records 2022-12-18T00:00:12Z DEBUG raw: server_find(None, version='2.251', no_members=False, servrole='IPA master') 2022-12-18T00:00:12Z DEBUG server_find(None, all=False, raw=False, version='2.251', no_members=False, pkey_only=False, servrole=('IPA master',)) 2022-12-18T00:00:12Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.251') 2022-12-18T00:00:12Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.251') 2022-12-18T00:00:12Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.251') 2022-12-18T00:00:12Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.251', pkey_only=False) 2022-12-18T00:00:12Z DEBUG raw: dnszone_show(, version='2.251') 2022-12-18T00:00:12Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:12Z DEBUG raw: location_find(None, version='2.251') 2022-12-18T00:00:12Z DEBUG location_find(None, all=False, raw=False, version='2.251', pkey_only=False) 2022-12-18T00:00:14Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-18T00:00:14Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-18T00:00:14Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-18T00:00:14Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-18T00:00:14Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-18T00:00:14Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-18T00:00:14Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-18T00:00:14Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-18T00:00:14Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-18T00:00:14Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-18T00:00:14Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-18T00:00:14Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-18T00:00:14Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-18T00:00:14Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-18T00:00:14Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-18T00:00:14Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-18T00:00:14Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-18T00:00:15Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-18T00:00:15Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-18T00:00:15Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-18T00:00:15Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-18T00:00:15Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-18T00:00:15Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-18T00:00:15Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-18T00:00:16Z DEBUG Created connection context.ldap2_140192305984656 2022-12-18T00:00:16Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-18T00:00:16Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-18T00:00:16Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-18T00:00:16Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-18T00:00:16Z DEBUG Configuring SID generation 2022-12-18T00:00:16Z DEBUG [1/8]: creating samba domain object 2022-12-18T00:00:16Z DEBUG step duration: SID generation __create_samba_domain_object 0.02 sec 2022-12-18T00:00:16Z DEBUG [2/8]: adding admin(group) SIDs 2022-12-18T00:00:16Z DEBUG step duration: SID generation __add_admin_sids 0.01 sec 2022-12-18T00:00:16Z DEBUG [3/8]: adding RID bases 2022-12-18T00:00:16Z DEBUG [LDAPEntry(ipapython.dn.DN('cn=REDACTED_DOMAIN.COM_id_range,cn=ranges,cn=etc,dc=redacted_domain,dc=com'), {'objectClass': [b'top', b'ipaIDrange', b'ipaDomainIDRange'], 'cn': [b'REDACTED_DOMAIN.COM_id_range'], 'ipaBaseID': [b'1382800000'], 'ipaIDRangeSize': [b'200000'], 'ipaRangeType': ['ipa-local']})] 2022-12-18T00:00:16Z DEBUG [LDAPEntry(ipapython.dn.DN('cn=REDACTED_DOMAIN.COM_id_range,cn=ranges,cn=etc,dc=redacted_domain,dc=com'), {'objectClass': [b'top', b'ipaIDrange', b'ipaDomainIDRange'], 'cn': [b'REDACTED_DOMAIN.COM_id_range'], 'ipaBaseID': [b'1382800000'], 'ipaIDRangeSize': [b'200000'], 'ipaRangeType': ['ipa-local']})] 2022-12-18T00:00:16Z DEBUG step duration: SID generation __add_rid_bases 0.00 sec 2022-12-18T00:00:16Z DEBUG [4/8]: updating Kerberos config 2022-12-18T00:00:16Z DEBUG 'dns_lookup_kdc' already set to 'true', nothing to do. 2022-12-18T00:00:16Z DEBUG step duration: SID generation __update_krb5_conf 0.00 sec 2022-12-18T00:00:16Z DEBUG [5/8]: activating sidgen task 2022-12-18T00:00:16Z DEBUG Starting external process 2022-12-18T00:00:16Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpicdzqo2i', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-18T00:00:16Z DEBUG Process finished, return code=0 2022-12-18T00:00:16Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: ipa-sidgen-task add nsslapd-pluginPath: libipa_sidgen_task add nsslapd-pluginInitfunc: sidgen_task_init add nsslapd-pluginType: object add nsslapd-pluginEnabled: on add nsslapd-pluginId: ipa_sidgen_task add nsslapd-pluginVersion: 1.0 add nsslapd-pluginVendor: RedHat add nsslapd-pluginDescription: Generate SIDs for existing user and group entries adding new entry "cn=ipa-sidgen-task,cn=plugins,cn=config" modify complete add objectClass: top extensibleObject add cn: ipa-sidgen-task adding new entry "cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2022-12-18T00:00:16Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-18T00:00:16Z DEBUG step duration: SID generation __add_sidgen_task 0.04 sec 2022-12-18T00:00:16Z DEBUG [6/8]: restarting Directory Server to take MS PAC and LDAP plugins changes into account 2022-12-18T00:00:16Z DEBUG Destroyed connection context.ldap2_140192305984656 2022-12-18T00:00:16Z DEBUG Starting external process 2022-12-18T00:00:16Z DEBUG args=['/bin/systemctl', 'restart', 'dirsrv@REDACTED_DOMAIN-COM.service'] 2022-12-18T00:00:23Z DEBUG Process finished, return code=0 2022-12-18T00:00:23Z DEBUG stdout= 2022-12-18T00:00:23Z DEBUG stderr= 2022-12-18T00:00:23Z DEBUG Restart of dirsrv@REDACTED_DOMAIN-COM.service complete 2022-12-18T00:00:23Z DEBUG Created connection context.ldap2_140192305984656 2022-12-18T00:00:23Z DEBUG step duration: SID generation __restart_dirsrv 7.19 sec 2022-12-18T00:00:23Z DEBUG [7/8]: adding fallback group 2022-12-18T00:00:23Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-18T00:00:23Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-18T00:00:23Z DEBUG Starting external process 2022-12-18T00:00:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpagyj7k45', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-18T00:00:23Z DEBUG Process finished, return code=0 2022-12-18T00:00:23Z DEBUG stdout=add cn: Default SMB Group add description: Fallback group for primary group RID, do not add users to this group add gidnumber: -1 add objectclass: top ipaobject posixgroup adding new entry "cn=Default SMB Group,cn=groups,cn=accounts,dc=redacted_domain,dc=com" modify complete 2022-12-18T00:00:23Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-18T00:00:23Z DEBUG step duration: SID generation __add_fallback_group 0.24 sec 2022-12-18T00:00:23Z DEBUG [8/8]: adding SIDs to existing users and groups 2022-12-18T00:00:23Z DEBUG Starting external process 2022-12-18T00:00:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/tmpmkj9kxf7', '-H', 'ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket', '-Y', 'EXTERNAL'] 2022-12-18T00:00:23Z DEBUG Process finished, return code=0 2022-12-18T00:00:23Z DEBUG stdout=add objectClass: top extensibleObject add cn: sidgen add nsslapd-basedn: dc=redacted_domain,dc=com add delay: 0 adding new entry "cn=sidgen,cn=ipa-sidgen-task,cn=tasks,cn=config" modify complete 2022-12-18T00:00:23Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-REDACTED_DOMAIN-COM.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2022-12-18T00:00:23Z DEBUG This step may take considerable amount of time, please wait.. 2022-12-18T00:00:24Z DEBUG step duration: SID generation __add_sids 1.02 sec 2022-12-18T00:00:24Z DEBUG Done. 2022-12-18T00:00:24Z DEBUG service duration: SID generation 8.52 sec 2022-12-18T00:00:24Z DEBUG raw: update_host_cifs_keytabs 2022-12-18T00:00:24Z DEBUG raw: adtrust_is_enabled(version='2.251') 2022-12-18T00:00:24Z DEBUG adtrust_is_enabled(version='2.251') 2022-12-18T00:00:24Z DEBUG AD Trusts are not enabled on this server 2022-12-18T00:00:26Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-18T00:00:26Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-18T00:00:26Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-18T00:00:26Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-18T00:00:26Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-18T00:00:26Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-18T00:00:26Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-18T00:00:26Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-18T00:00:26Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-18T00:00:26Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-18T00:00:27Z DEBUG Created connection context.ldap2_139735866196368 2022-12-18T00:00:27Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2022-12-18T00:00:27Z DEBUG Changing admin password 2022-12-18T00:00:27Z DEBUG Starting external process 2022-12-18T00:00:27Z DEBUG args=['/usr/bin/ldappasswd', '-H', 'ldap://master.redacted_domain.com', '-ZZ', '-x', '-D', 'cn=Directory Manager', '-y', '/var/lib/ipa/tmp4tggudqt', '-T', '/var/lib/ipa/tmpohp9g68o', 'uid=admin,cn=users,cn=accounts,dc=redacted_domain,dc=com'] 2022-12-18T00:00:27Z DEBUG Process finished, return code=0 2022-12-18T00:00:27Z DEBUG stdout= 2022-12-18T00:00:27Z DEBUG stderr= 2022-12-18T00:00:27Z DEBUG ldappasswd done 2022-12-18T00:00:57Z DEBUG importing all plugin modules in ipaserver.plugins... 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.aci 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.automember 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.automount 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.baseldap 2022-12-18T00:00:57Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.baseuser 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.batch 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.ca 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.caacl 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.cert 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.certmap 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.certprofile 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.config 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.delegation 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.dns 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.dogtag 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.group 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.hbac 2022-12-18T00:00:57Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.hbactest 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.host 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.idp 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.idrange 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.idviews 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.internal 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.join 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.ldap2 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.location 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.migration 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.misc 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.netgroup 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.otp 2022-12-18T00:00:57Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.otptoken 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.passwd 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.permission 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.ping 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.pkinit 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.privilege 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.rabase 2022-12-18T00:00:57Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.role 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.schema 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.selfservice 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.server 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.serverrole 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.serverroles 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.service 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.session 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.stageuser 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.subid 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.sudo 2022-12-18T00:00:57Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.sudorule 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.topology 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.trust 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.user 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.vault 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.virtual 2022-12-18T00:00:57Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.whoami 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2022-12-18T00:00:57Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.dns 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_changelog_maxage 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_pwpolicy 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2022-12-18T00:00:57Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2022-12-18T00:00:58Z DEBUG Created connection context.ldap2_140610326112848 2022-12-18T00:00:58Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2022-12-18T00:00:58Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket from SchemaCache 2022-12-18T00:00:58Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-REDACTED_DOMAIN-COM.socket conn= 2022-12-18T00:00:58Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2022-12-18T00:00:58Z DEBUG Set service ['KDC'] for master.redacted_domain.com to enabledService 2022-12-18T00:00:58Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2022-12-18T00:00:58Z DEBUG Set service ['KPASSWD'] for master.redacted_domain.com to enabledService 2022-12-18T00:00:58Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2022-12-18T00:00:58Z DEBUG Set service ['KEYS'] for master.redacted_domain.com to enabledService 2022-12-18T00:00:58Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2022-12-18T00:00:58Z DEBUG Set service ['CA'] for master.redacted_domain.com to enabledService 2022-12-18T00:00:58Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2022-12-18T00:00:58Z DEBUG Set service ['OTPD'] for master.redacted_domain.com to enabledService 2022-12-18T00:00:58Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2022-12-18T00:00:58Z DEBUG Set service ['HTTP'] for master.redacted_domain.com to enabledService 2022-12-18T00:00:58Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2022-12-18T00:00:58Z DEBUG Set service ['KRA'] for master.redacted_domain.com to enabledService 2022-12-18T00:00:58Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2022-12-18T00:00:58Z DEBUG Set service ['DNS'] for master.redacted_domain.com to enabledService 2022-12-18T00:00:58Z DEBUG update_entry modlist [(1, 'ipaconfigstring', [b'configuredService']), (0, 'ipaconfigstring', [b'enabledService'])] 2022-12-18T00:00:58Z DEBUG Set service ['DNSKeySync'] for master.redacted_domain.com to enabledService 2022-12-18T00:00:58Z DEBUG raw: dns_update_system_records(version='2.251') 2022-12-18T00:00:58Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG raw: server_find(None, version='2.251', no_members=False, servrole='IPA master') 2022-12-18T00:00:58Z DEBUG server_find(None, all=False, raw=False, version='2.251', no_members=False, pkey_only=False, servrole=('IPA master',)) 2022-12-18T00:00:58Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.251') 2022-12-18T00:00:58Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.251') 2022-12-18T00:00:58Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.251', pkey_only=False) 2022-12-18T00:00:58Z DEBUG raw: server_role_find(None, server_server='master.redacted_domain.com', status='enabled', include_master=True, version='2.251') 2022-12-18T00:00:58Z DEBUG server_role_find(None, server_server='master.redacted_domain.com', status='enabled', include_master=True, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG raw: dnszone_show(, version='2.251') 2022-12-18T00:00:58Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG Name master.redacted_domain.com. resolved to {UnsafeIPAddress('172.16.0.21'), UnsafeIPAddress('fe80::5054:ff:fe00:10')} 2022-12-18T00:00:58Z WARNING Invalid IP address fe80::5054:ff:fe00:10 for master.redacted_domain.com.: cannot use link-local IP address fe80::5054:ff:fe00:10 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"REDACTED_DOMAIN.COM"'], urirecord=['0 100 "krb5srv:m:tcp:master.redacted_domain.com."', '0 100 "krb5srv:m:udp:master.redacted_domain.com."'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_mod(, , txtrecord=('"REDACTED_DOMAIN.COM"',), urirecord=('0 100 "krb5srv:m:tcp:master.redacted_domain.com."', '0 100 "krb5srv:m:udp:master.redacted_domain.com."'), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG update_entry modlist [(2, 'urirecord', [b'0 100 "krb5srv:m:tcp:master.redacted_domain.com."', b'0 100 "krb5srv:m:udp:master.redacted_domain.com."']), (1, 'txtrecord', [b'REDACTED_DOMAIN.COM']), (0, 'txtrecord', [b'"REDACTED_DOMAIN.COM"']), (2, 'idnstemplateattribute;cnamerecord', [b'_kerberos.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 master.redacted_domain.com.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 master.redacted_domain.com.',), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 389 master.redacted_domain.com.'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 389 master.redacted_domain.com.',), force=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 master.redacted_domain.com.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 master.redacted_domain.com.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 master.redacted_domain.com.'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 master.redacted_domain.com.',), force=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 master.redacted_domain.com.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 master.redacted_domain.com.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 master.redacted_domain.com.'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 master.redacted_domain.com.',), force=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 master.redacted_domain.com.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 master.redacted_domain.com.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 master.redacted_domain.com.'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 master.redacted_domain.com.',), force=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 master.redacted_domain.com.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 master.redacted_domain.com.',), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 88 master.redacted_domain.com.'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 88 master.redacted_domain.com.',), force=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:58Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:58Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2022-12-18T00:00:59Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 master.redacted_domain.com.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:59Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 master.redacted_domain.com.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:59Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 464 master.redacted_domain.com.'], version='2.251') 2022-12-18T00:00:59Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 464 master.redacted_domain.com.',), force=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:59Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:59Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:59Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2022-12-18T00:00:59Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 master.redacted_domain.com.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:59Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 master.redacted_domain.com.',), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:59Z DEBUG raw: dnsrecord_add(, , srvrecord=['0 100 464 master.redacted_domain.com.'], version='2.251') 2022-12-18T00:00:59Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, srvrecord=('0 100 464 master.redacted_domain.com.',), force=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:59Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:59Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:59Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2022-12-18T00:00:59Z DEBUG raw: dnsrecord_mod(, , urirecord=['0 100 "krb5srv:m:tcp:master.redacted_domain.com."', '0 100 "krb5srv:m:udp:master.redacted_domain.com."'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:59Z DEBUG dnsrecord_mod(, , urirecord=('0 100 "krb5srv:m:tcp:master.redacted_domain.com."', '0 100 "krb5srv:m:udp:master.redacted_domain.com."'), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:59Z DEBUG raw: dnsrecord_add(, , urirecord=['0 100 "krb5srv:m:tcp:master.redacted_domain.com."', '0 100 "krb5srv:m:udp:master.redacted_domain.com."'], version='2.251') 2022-12-18T00:00:59Z DEBUG dnsrecord_add(, , a_extra_create_reverse=False, aaaa_extra_create_reverse=False, urirecord=('0 100 "krb5srv:m:tcp:master.redacted_domain.com."', '0 100 "krb5srv:m:udp:master.redacted_domain.com."'), force=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:59Z DEBUG raw: dnsrecord_mod(, , setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.251') 2022-12-18T00:00:59Z DEBUG dnsrecord_mod(, , setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:59Z DEBUG update_entry modlist [(2, 'idnstemplateattribute;cnamerecord', [b'_kpasswd.\\{substitutionvariable_ipalocation\\}._locations']), (0, 'objectclass', [b'idnsTemplateObject'])] 2022-12-18T00:00:59Z DEBUG raw: dnsrecord_mod(, , arecord=['172.16.0.21'], version='2.251') 2022-12-18T00:00:59Z DEBUG dnsrecord_mod(, , arecord=('172.16.0.21',), rights=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:59Z DEBUG raw: dnsrecord_add(, , arecord=['172.16.0.21'], version='2.251') 2022-12-18T00:00:59Z DEBUG dnsrecord_add(, , arecord=('172.16.0.21',), a_extra_create_reverse=False, aaaa_extra_create_reverse=False, force=False, structured=False, all=False, raw=False, version='2.251') 2022-12-18T00:00:59Z DEBUG raw: location_find(None, version='2.251') 2022-12-18T00:00:59Z DEBUG location_find(None, all=False, raw=False, version='2.251', pkey_only=False) 2022-12-18T00:00:59Z DEBUG Starting external process 2022-12-18T00:00:59Z DEBUG args=['/bin/systemctl', 'enable', 'ipa.service'] 2022-12-18T00:00:59Z DEBUG Process finished, return code=0 2022-12-18T00:00:59Z DEBUG stdout= 2022-12-18T00:00:59Z DEBUG stderr=Created symlink /etc/systemd/system/multi-user.target.wants/ipa.service → /usr/lib/systemd/system/ipa.service. 2022-12-18T00:00:59Z DEBUG Starting external process 2022-12-18T00:00:59Z DEBUG args=['/bin/systemctl', 'restart', 'ipa.service'] 2022-12-18T00:01:19Z DEBUG Process finished, return code=0 2022-12-18T00:01:19Z DEBUG stdout= 2022-12-18T00:01:19Z DEBUG stderr= 2022-12-18T00:01:19Z DEBUG Starting external process 2022-12-18T00:01:19Z DEBUG args=['/bin/systemctl', 'is-active', 'ipa.service'] 2022-12-18T00:01:19Z DEBUG Process finished, return code=0 2022-12-18T00:01:19Z DEBUG stdout=active 2022-12-18T00:01:19Z DEBUG stderr= 2022-12-18T00:01:19Z DEBUG Restart of ipa.service complete